Defeating DoS: SIA vs AIA
A core architectural tenet of VSS is prioritizing Subject Information Access (SIA) over Authority Information Access (AIA). Chasing AIA URIs supplied in unvalidated end-entity certificates exposes PKI engines to severe "Zip Bomb" Denial of Service attacks. By relying on SIA (a top-down whitelist from trusted issuers) or failing closed on the local cache, VSS maintains high availability against adversarial payloads.