Absolutely, to the point that it's ridiculous to compare it to client-side Javascript.
Comodo was breached and the certificates were revoked using the theoretically-sound, tested, and implemented PKI solution.
Weeeellll actually... Mozilla, Google, MS had to rush out a code patch to manually blacklist the fraudulent certs. Revocation checking is implemented so weakly in browsers and other HTTPS clients that it just doesn't work when it comes down to it.
Of course, the browser Javascript doesn't have any problems of weak revocation checking. It's simply altogether unauthenticated in the first place!
Absolutely, to the point that it's ridiculous to compare it to client-side Javascript.
Comodo was breached and the certificates were revoked using the theoretically-sound, tested, and implemented PKI solution.
Weeeellll actually... Mozilla, Google, MS had to rush out a code patch to manually blacklist the fraudulent certs. Revocation checking is implemented so weakly in browsers and other HTTPS clients that it just doesn't work when it comes down to it.
Of course, the browser Javascript doesn't have any problems of weak revocation checking. It's simply altogether unauthenticated in the first place!