> It sure seems to me that short-lived certificates tend to rotate out far more often than they need to be revoked.

For large majority of companies, would they even spot that their keys have been stolen? That's a few steps before revocation itself.

