Revocation Checking and Chrome’s CRL

Adam Langley (via Wolf Rentzsch): But an attacker who can intercept HTTPS connections can also make online revocation checks appear to fail and so bypass the revocation checks! In cases where the attacker can only intercept a subset of a victim’s traffic (i.e. the SSL traffic but not the revocation checks), the attacker is likely … Continue reading Revocation Checking and Chrome’s CRL