Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are new solutions for CRL just last month:

https://hacks.mozilla.org/2025/08/crlite-fast-private-and-co...



This has existed for a while. It doesn’t address another major issue with revocation: user agents that aren’t browsers don’t implement it.


Yup. If your primary goal was fast, efficient certificate revocation, then having certs that still take 90 days to expire rather than 2 years is not the solution you'd come up with.

CRLite updates every 12 hours.


If you have short validity times for certificates it also means you have shorter CRL.


Not by definition. The main issue is mass revocation events: the CRL is still going to initially contain up to 100% of certs currently active, and the number of active certs won't meaningfully change.

It'll rapidly shrink over time as certs expire, but you still have to deal with that initial massive set.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: