- From: Samuel Rinnetmäki <samuel.rinnetmaki@findy.fi>
- Date: Fri, 25 Sep 2026 08:04:11 +0000
- To: "public-credentials@w3.org" <public-credentials@w3.org>
Received on Sunday, 27 September 2026 21:33:07 UTC
bumblefudge is right that publishing revocation history would leak a great deal. I disagree. If revocation information is publicly available, anyone interested in the changes could build a watcher that looks the status list at hourly or daily intervals and know the exact time when a certain credential was revoked. If the revocation history was published by the issuer (or the status list maintainer) by an API, it would not reveal any secret, hidden, confidential or non-public information. Samuel
Received on Sunday, 27 September 2026 21:33:07 UTC