# Windows Live Mail revocation warning

**URL:** https://community.letsencrypt.org/t/windows-live-mail-revocation-warning/26310
**Category:** Issuance Tech
**Created:** [January 24, 2017, 10:45am UTC](https://community.letsencrypt.org/t/windows-live-mail-revocation-warning/26310 "2017-01-24T10:45:37Z")
**Posts on this page:** 1
**Showing post:** 15

<div class="post-metadata">

### Author: ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)
#### Post date: [March 13, 2017, 4:24pm UTC](https://community.letsencrypt.org/t/windows-live-mail-revocation-warning/26310/15 "2017-03-13T16:24:59Z")

</div>

(Reopened the original topic and merged the previous posts.)

Compared to OCSP, CRL is quite the bandwidth hog. It’s essentially a file containing a list of _all_ revoked certificates from a particular CA (though some partitioning is possible to improve performance), and every user needs to fetch the whole file. Cloudflare had a [blog post](https://blog.cloudflare.com/the-hard-costs-of-heartbleed/) on this a few years ago during the Heartbleed fiasco (during which a lot of certificates were revoked). They estimated the bandwidth cost for the revocations of just one CA at about $400,000.

Let’s Encrypt probably has (at least) an order of magnitude more active certificates, so we might be talking about $4M for the next Heartbleed. That’s more than what it costs to run Let’s Encrypt for a year otherwise (about $3M). Even without a similar event, the cost for CRL would be significant - about 25,000 certificates are revoked each month (based on stats from December).

Technical reasons aside, it’s probably simply too costly.

---

_[View the full topic](https://community.letsencrypt.org/t/windows-live-mail-revocation-warning/26310)._
