Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not quite. In the case of OCSP, in the absence of OCSP stapling, all TLS connections are verified with an external server(s).

In that case of SafeBrowsing however, as noted in the article, for those URLs whose hash prefix doesn't match one of the hashes on one of the blacklists, the browser doesn't contact any other server. Only when there's a partial match does the browser ask for a full hash from the SafeBrowsing server.

Source: I'm a Chrome SafeBrowsing engineer.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: