Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's because CRLs/OCSP sucks so now short expiration is rolling out.




CRL doesn’t suck it is just not easy problem on web scale.

But seems like there is feasible solution: https://hacks.mozilla.org/2025/08/crlite-fast-private-and-co...


AKA they suck in this context

Was CRL designed with this context in mind?

Doesn’t matter. I think we’re fighting semantics.

Certificates are cached trust, and all the cache busting problem applies here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: