Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I also love OCSP stapling but there are some limitations: - webserver need to implement it - admin need to enable it - webserver need internet access

Maybe they saw with some telemetry that very few website actually enable OCSP stampling and decided to implement a fix that cover all certs and can really be deployed



Firefox Telemetry shows Beta 104 users encountered stapling on 13.95% of TLS handshakes. [1]

The stapling telemetry is no longer turned on in Release [2], and even if it were, you have to do special things to look at Release data, but some years back (~2018 maybe?) I remember Release stapling was substantially lower than the more tech-savvy Beta and Nightly populations. Which is pretty normal, as tech-oriented sites are more likely to turn on advanced features.

[1] https://telemetry.mozilla.org/new-pipeline/dist.html#!cumula...

[2] "prerelease" https://probes.telemetry.mozilla.org/?search=stapl&view=deta...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: