Google’s Chrome browser “blindly” trusting Heartbleed affect

User avatar
Roderunner
5StarLounger
Posts: 1021
Joined: 23 Jan 2011, 01:52
Location: Witness Protection Program.

Google’s Chrome browser “blindly” trusting Heartbleed affect

Post by Roderunner »

The problem within Chrome is CRLSet, which catalogs revoked security certificates. If a website has been compromised and had their security certificate taken away, CRLSet should know about it and give you a warning before proceeding. Gibson Research Corporation claims Google’s CRLSet — used in lieu of the online certificate status protocol — misses about 98% of revoked certificates.
http://www.slashgear.com/googles-chrome ... -29326996/
Windows 11 Home 22H2

Regards,
George.

User avatar
HansV
Administrator
Posts: 78461
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Google’s Chrome browser “blindly” trusting Heartbleed af

Post by HansV »

This may be another hype - Google's CRLSet is continuously being updated.
Ars Technica, for example, have updated their article about this subject with a kind of disclaimer.
Best wishes,
Hans

User avatar
Roderunner
5StarLounger
Posts: 1021
Joined: 23 Jan 2011, 01:52
Location: Witness Protection Program.

Re: Google’s Chrome browser “blindly” trusting Heartbleed af

Post by Roderunner »

Hi Hans,
It does'nt affect me as I use FF.
Windows 11 Home 22H2

Regards,
George.