That will eliminate privacy concerns -- no compliant TLS implementation should fetch a OCSP ticket given a stapled response -- while still allowing for broad non-browser support.
That will eliminate privacy concerns -- no compliant TLS implementation should fetch a OCSP ticket given a stapled response -- while still allowing for broad non-browser support.
I don't know if they've fixed it yet. I doubt it though - they were pretty aggressive in their assertion that violating must-staple wasn't a concern.
Apple and Firefox are all working on out-of-band revocation information based on CRL data. Presumably Chrome and its family are going to go down that path too, but I'm not sure I've heard commitments from them yet.
Firefox has the best documentation on what's happening: https://blog.mozilla.org/security/2020/01/09/crlite-part-1-a...
[0]: https://www.troyhunt.com/extended-validation-certificates-ar... [1]: https://blog.chromium.org/2020/08/helping-people-spot-spoofs... [2]: https://www.reddit.com/r/chrome/comments/h11gde/how_do_i_sto... [3]: https://www.wired.com/story/google-chrome-kill-url-first-ste...
At the very least it should have a [...] and not completely hide the fact that there is a URL.
The handful of streaming and social media sites can always go to a big commercial CA and spend a few hundred bucks a year on certs that do whatever they need.