No More SSL Revocation Checking For Chrome
New submitter mwehle writes with this bit from Ars Technica: "Google's Chrome browser will stop relying on a decades-old method for ensuring secure sockets layer certificates are valid after one of the company's top engineers compared it to seat belts that break when they are needed most. The browser will stop querying CRL, or certificate revocation lists, and databases that rely on OCSP, or online certificate status protocol, Google researcher Adam Langley said in a blog post published on Sunday. He said the services, which browsers are supposed to query before trusting a credential for an SSL-protected address, don't make end users safer because Chrome and most other browsers establish the connection even when the services aren't able to ensure a certificate hasn't been tampered with."
Why?
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
Except now Google is presenting itself as an authority on the status of certificates that it has no business doing so with to the users of chrome.
This is a bad thing.