Hacker News new | past | comments | ask | show | jobs | submit login

Obviously stapling improves on OCSP, and OCSP is flawed. But OCSP is better than nothing. It's not 100% useless - if a server or a cert has been owned, OCSP will protect the user from that. If the user has been owned, only stapling will save them, so obviously a move towards stapling is a good idea.

But don't let the perfect be the enemy of the "better than nothing".




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: