I think it's more about revocation not working in practice. So the only solution is a short TTL.