Dennis Jackson

@dennisjackson.bsky.social

Cryptography @ Mozilla

New paper(!) on the "clubcard" data structure that we're using for WebPKI revocation checks in Firefox. A clubcard is a membership test for an r element subset of an n element set. Size is ~1.13 log(n choose r) bits. Or (better!) ~1.13 Σ log(n_i choose r_i) where i indexes blocks of a partition.

ePrint Updates@eprint.ing.bot · 2y ago

Clubcards for the WebPKI: smaller certificate revocation tests in theory and practice (John M. Schanck) ia.cr/2025/610

Abstract. CRLite is a low-bandwidth, low-latency, privacy-preserving mechanism for distributing certificate revocation data. A CRLite aggregator periodically encodes revocation data into a compact static hash set, or membership test, which can can be downloaded by clients and queried privately. We present a novel data-structure for membership tests, which we call a clubcard, and we evaluate the encoding efficiency of clubcards using data from Mozilla’s CRLite infrastructure.

As of November 2024, the WebPKI contains over 900 million valid certificates and over 8 million revoked certificates. We describe an instantiation of CRLite that encodes the revocation status of these certificates in a 6.7 MB package. This is 54% smaller than the original instantiation of CRLite presented at the 2017 IEEE Symposium on Security and Privacy, and it is 21% smaller than the lower bound claimed in that work.

A sequence of clubcards can encode a dynamic dataset like the WebPKI revocation set. Using data from late 2024 again, we find that clubcards encoding 6 hour delta updates to the WebPKI can be compressed to 26.8 kB on average—a size that makes CRLite truly practical.

We have extended Mozilla’s CRLite infrastructure so that it can generate clubcards, and we have added client-side support for this system to Firefox. We report on some performance aspects of our implementation, which is currently the default revocation checking mechanism in Firefox Nightly, and we propose strategies for further reducing the bandwidth requirements of CRLite.

Ooooh this is an excellent application of Privacy Pass, the anonymous credential scheme we originally designed to ameliorate the pain of Cloudflare CAPTCHAs on Tor. Authenticate with a paid account to obtain tokens, then anonymously redeem them to make unlinkable searches.

Kagi HQ@kagi.com · 2y ago

Announcing Kagi Privacy Pass! Kagi already respects your privacy when you search. With Privacy Pass, we’re taking it a step further by adding an extra layer of anonymity to ensure your searches are completely unlinkable to your account🔒 Learn more: blog.kagi.com/kagi-privacy...

At the top, the text 'Kagi Privacy Pass' is displayed alongside an illustration of Kagi’s mascot, which is a cartoon dog, lying down next to a yellow lock icon with a keyhole. Below, a user interface panel shows a toggle switch labeled 'Authenticate via Privacy Pass,' which is turned on. The panel also displays 'Remaining tokens: 486,' 'Status: Ready,' and a description: 'Searching on Kagi is already privacy-respecting. Authenticating via Privacy Pass adds an additional layer of anonymity, ensuring your searches remain completely unlinkable to your account.' A 'Learn more' link is included at the bottom.