> the client software can probably distrust certain trusted verifiers
Any client can do whatever they want with the information, that's right.
> or even use a public list of such revocations.
Revocation is deletion, so it's hard to enumerate revocations.