4 ms·
That does seem like a strange argument given that the safebrowsing database is essentially just a giant bloom filter containing many more entries (probably) tha
by thirsteh 13y ago
That does seem like a strange argument given that the safebrowsing database is essentially just a giant bloom filter containing many more entries (probably) than there are revoked SSL certificates.
The false positive verification could be done (for anything other than e.g. google.com's cert) with a call to Google's servers, I suppose.
- zaroth 13y agoA ~20MB bloom filter could have room for 10 million revoked certificates, with a .001 (1 in 1000) false positive rate. Moving either the false positive rate or the number of revoked certificates by an order of magnitude also increases size of the bloom filter an order of magnitude. For privacy reasons you don't want the browser asking 'is certificate X revoked' (OSCP) you want the browser asking 'give me the latest list of revoked certificates under Root CA X' (CRLs) and that starts to become a prohibitively large download. "OSCP Stapling" fixes the privacy problem, because the web server is the one asking for the OSCP response, and then caching it and providing it proactively to clients when they first connect. What we could do is extend the HSTS header to provide a way for the web server to indicate OSCP MUST be Stapled, then the browser can fail hard if OSCP is not provided. There's still a privacy issue of your browser basically bookmarking every HSTS site that you visit, and probably not providing an easy way to know that happening or clear that out. For example, if I clear my browsing history, should it reset my HSTS lists?
- thirsteh 13y ago> There's still a privacy issue of your browser basically bookmarking every HSTS site that you visit, and probably not providing an easy way to know that happening or clear that out. For example, if I clear my browsing history, should it reset my HSTS lists? Agree. I'm suggesting the client maintains an up-to-date bloom filter for all revoked certificates, and only contacts Google when something detects as positive (to verify that it is not a false positive.) You will still leak "I visited foo.com" if someone has compromised your SSL connection to google.com, but at least it doesn't leak your entire browsing history.