OCSP is a good thing, and the web - and your signed applications - are better off with it.
OCSP is a good thing, and the web - and your signed applications - are better off with it.
Active OCSP is far from being considered a good thing universally.
Spoiler alert, you've probably already used OCSP on the web.
That’s why CT came around.
Some background for those unfamiliar.
https://medium.com/@alexeysamoshkin/how-ssl-certificate-revo...
Although OCSP stapling is used more now IIRC.
HN doesn’t set OCSP must staple so we’re still a while away from being able to trust it.
It's worth noting a couple differences between HTTPS OCSP and Developer ID OCSP. First, with Developer ID, the only DNS request is for ocsp.apple.com, so the DNS request by itself doesn't expose any information about the Mac app being launched, unlike with HTTPS.
Second, the caching of Developer ID OCSP responses tends to be much much shorter than for HTTPS. Prior to Thursday's outage, the standard cache length for Developer ID OCSP responses seemed to be 5 minutes. (Apple seems to have raised it to 12 hours now.) In contrast, I just checked the latest response in my OCSP cache, which was for http://ocsp.digicert.com, and its validity is 7 days. So the rate at which Developer ID OCSP requests are made seems to be much higher than for HTTPS, and thus there's greater chance of exposure.