Easily test your browser's response to revoked certificates

https://revoked.grc.com/

Does anyone here watch or listen to Security Now!? It’s great.

Steve Gibson set up the above web page with a revoked certificate. Just see what happens when you try to visit the page, to see how your browser responds. It should issue a warning saying that the certificate has been revoked. If it doesn’t, that’s a security concern.

If your browser let’s you view the page above (https://revoked.grc.com/) you can read all about issue there. If it doesn’t (which is preferable) you can read all about it (and I think it’s interesting) here:

By the way, Chrome is focused on speed and seems to allow you to visit the page with no warnings. Firefox handles it much better and blocks it.

edit: It turns out this test may not be reliable for Chrome because they’ve manually added an exception for this site. Presumably because it’s embarrassing that Chrome’s system is essentially broken.
There are four pages about this on grc.com, linked to in this post further down. There’s loads of information there. Sorry I’ve made such a hash of presenting it here!:blush:

3 Likes

On chrome, can see the whole site

1 Like

Chromium ubuntu doesn’t even show such a checkbox :upside_down:

1 Like