If anything, now that everything is connected to the internet you want shorter revocations (like days, weeks or months). That way the potential for abuse is shorter and the path for renewal is better trodden by organizations (ie less likely to forget about an expiring cert).
[1] https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...
[2] https://en.m.wikipedia.org/wiki/RSA_BSAFE
[3] https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)
https://www.mail-archive.com/cryptography@metzdowd.com/msg12...
It’s describing the same tactics, but a different protocol. Honestly, just crack open the SSL spec. In hindsight, it’s pretty obvious it was intentionally over-complicated.
The Wireguard protocol attempts to fix these issues by hardcoding everything behind a protocol version number. It’s vastly easier to implement and configure properly.