Google is changing the system that Chrome uses for certificate revocation. Chrome will no longer use online revocation checks to revoke certificates. Instead, Chrome will use the existing update system in the browser to accomplish this task. The change is in the face of mounting evidence that the CA system is inherently flawed, Google officials say. Researchers have shown this to be possible in a number of scenarios, including the BEAST SSL attack developed by Thai Duong and Juliano Rizzo last year. Google s Adam Langley wrote in a blog post on the changes.
Source: https://threatpost.com/google-stop-using-online-crl-checks-chrome-020712/76180/

