Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Technically AFAIK, the revocation list could be turned into a Bloom filter (or one of its alternatives) and updated from the servers periodically.

edit: on 2nd thought just a list of hashed cert ids could suffice because it is hard to imagine there ever being thousands of revocations.

That way the provider would have no knowledge of which certs are being verified.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: