9 ms·
This is some of the most awful writing I've seen on the HN front page in a while. I'm sure if you're well-versed in the issues surrounding revocation the discus
by datapolitical 12y ago
This is some of the most awful writing I've seen on the HN front page in a while. I'm sure if you're well-versed in the issues surrounding revocation the discussion makes a great deal of sense.
For the rest of us, it's a forrest of technical jargon, which is stunning to me given that the concepts at play here aren't insanely complicated.
>So I think the claim is that doing blocking OCSP lookups is a good idea because, if you use CAPI on Windows, then you might cache 50 OCSP responses for a given CA certificate. Then you'll download and cache a CRL for a while and then, depending on whether the CA splits their CRLs, you might have some revocations cached for a site that you visit.
- nkurz 12y agoI'm sure if you're well-versed in the issues surrounding revocation the discussion makes a great deal of sense. I think you've summarized the traditional appeal of Hacker News: items for experts, written by experts, discussed by experts. Even if it's not a field that I understand (what better way to learn?) I'm always glad to see these articles on the front page, for it means the real HN is still alive, deep within.