- From: Steffen Schwalm <Steffen.Schwalm@msg.group>
- Date: Mon, 28 Sep 2026 03:34:41 +0000
- To: Samuel Rinnetmäki <samuel.rinnetmaki@findy.fi>, "public-credentials@w3.org" <public-credentials@w3.org>
Received on Monday, 28 September 2026 03:34:48 UTC
Hi all,
if the status list or similar is not publicly available how should verifier check if my credential is valid? Would require Trust Verifier list or similar as additional effort – not sure if this is practically meaningful in all cases
Von: Samuel Rinnetmäki <samuel.rinnetmaki@findy.fi>
Gesendet: Freitag, 25. September 2026 10:04
An: public-credentials@w3.org
Betreff: Re: Historical status
Caution: This email originated from outside of the organization. Despite an upstream security check of attachments and links by Microsoft Defender for Office, a residual risk always remains. Only open attachments and links from known and trusted senders.
bumblefudge is right that publishing revocation history would leak a great deal.
I disagree.
If revocation information is publicly available, anyone interested in the changes could build a watcher that looks the status list at hourly or daily intervals and know the exact time when a certain credential was revoked.
If the revocation history was published by the issuer (or the status list maintainer) by an API, it would not reveal any secret, hidden, confidential or non-public information.
Samuel
Received on Monday, 28 September 2026 03:34:48 UTC