nBlacklists
have numerous problems
nNot
issued frequently enough to be effective against a serious attack
nExpensive
to distribute (size & bandwidth)
nVulnerable
to simple DOS attacks
nIf
you block on lack of CRL access, why have off-line support in the first place?