4 ms·
Has anyone explored using a technique like a Bloom filter or partial hash matching (like haveibeenpwned does) as a preliminary step for CRL lookups? You could d
by alwaysbeconsing 3y ago
Has anyone explored using a technique like a Bloom filter or partial hash matching (like haveibeenpwned does) as a preliminary step for CRL lookups? You could do a cheap initial query, and if you get a negative, you're good. You only have to do the full expensive one if you get a positive, to ensure that it's a true positive. Which should be rare since most certs that are presented won't be revoked.
- Operyl 3y agoHonestly? I don't think it makes sense for us to continue down the path where the clients connect to the CA to verify status. While I trust most CAs (like LE), the less information a client has to expose to one the better.
- coffee-- 3y agohttps://blog.mozilla.org/security/2020/01/09/crlite-part-1-all-web-pki-revocations-compressed/ https://blog.mozilla.org/security/2020/01/09/crlite-part-1-a...