On Thu, Sep 8, 2011 at 10:12 AM, Chris Palmer <[email protected]> wrote:

> On Thu, Sep 8, 2011 at 9:33 AM, nlsp <[email protected]> wrote:
>
> > This boils down to whether it is okay to prioritize availability over
> > security.
>
> Availability is a security guarantee just like confidentiality or
> integrity.
>
> > Still, the actual question remains: does the android browser
> > support CRL or OCSP in any form?
>
> Even desktop Firefox has security.OCSP.require set to false. Read the
> Imperial Violet post again carefully.
>
> > And since CRLs can be cached, it would be perfectly sane to have a
> > cached CRL on device for an intermediate that has been compromised,
>
> They get kind of big.
>

This can be addressed, and there's already some work up on imperialviolet
about it: http://www.imperialviolet.org/2011/04/29/filters.html

Geremy Condra

-- 
You received this message because you are subscribed to the Google Groups 
"Android Security Discussions" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/android-security-discuss?hl=en.

Reply via email to