Ever-growing CRL?
Ever-growing CRL?
Posted Dec 9, 2024 21:48 UTC (Mon) by NYKevin (subscriber, #129325)In reply to: Ever-growing CRL? by tialaramex
Parent article: Let's Encrypt sets date for ending OCSP support
And this leads us to the broader problem with EV: You are allowing third parties to display (effectively) arbitrary text in the browser's trusted UI, in green and right next to a lock symbol, with the intent that users accept that text at face value. There are probably a thousand different kinds of mischief that attackers can make with that. The only reason they mostly didn't bother is because, back when EV was still a thing, you didn't even need HTTPS for phishing in the first place since so much of the web was still on plain HTTP.
