AW: Historical status

Hi all,

if the status list or similar is not publicly available how should verifier check if my credential is valid? Would require Trust Verifier list or similar as additional effort – not sure if this is practically meaningful in all cases

Von: Samuel Rinnetmäki <samuel.rinnetmaki@findy.fi>
Gesendet: Freitag, 25. September 2026 10:04
An: public-credentials@w3.org
Betreff: Re: Historical status


Caution: This email originated from outside of the organization. Despite an upstream security check of attachments and links by Microsoft Defender for Office, a residual risk always remains. Only open attachments and links from known and trusted senders.

bumblefudge is right that publishing revocation history would leak a great deal.
I disagree.

If revocation information is publicly available, anyone interested in the changes could build a watcher that looks the status list at hourly or daily intervals and know the exact time when a certain credential was revoked.

If the revocation history was published by the issuer (or the status list maintainer) by an API, it would not reveal any secret, hidden, confidential or non-public information.

      Samuel

Received on Monday, 28 September 2026 03:34:48 UTC