4 ms·
> 2. Don't HPKP your blog. Don't HPKP your cat-sharing starting. Key pinning is a good thing, but it doesn't need to be universally deployed. Just to be clear,
by jb613 10y ago
> 2. Don't HPKP your blog. Don't HPKP your cat-sharing starting. Key pinning is a good thing, but it doesn't need to be universally deployed.
Just to be clear, this is equivalent to saying don't bother with SSL for your blog or cat-sharing site (because without pinning someone else can get a cert for your blog/cat-sharing site).
> the ability for sites with low security requirements to opt out of HPKP.
opt out?! It's off by default.
> Remember, the threat model for HPKP isn't fraudsters or trolls; it's state-level adversaries.
Again, by saying HPKP is only for high security sites (now you're saying only for those threatened by state-level adversaries) you are essentially saying SSL is useless for everything less.
- vfaronov 10y agoNot bothering with TLS for a blog is likely to be a good idea.
- KMag 10y agoWell, TLS (allong with access controls) for his sing-along blog would have really helped Dr. Horrible stay ahead of the authorities. In all seriousness, though, there are plenty of blogs where which page a user visits might, for instance, out a gay teen via gateway logs, hint about a private health issue, etc.
- jb613 10y agoThat's outdated thinking. Look around at the efforts in past ~year for getting SSL everywhere. Non-SSL sites already suffer Google PageRanking[1] (maybe you want Google visibility for your blog or cat-sharing site), other consequences are not far off. [1] HTTPS as a ranking signal: https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html https://webmasters.googleblog.com/2014/08/https-as-ranking-s...
- bulatb 10y agoI think "opt out" means opting out of being able to be pinned, not just choosing not to pin. Instead of pinning a certificate, you might pin "This domain will not be pinning a certificate before $date."
- jb613 10y agoFine but then you're leaving open the possibility for others to get a cert for your domain.
- pcl 10y ago> > the ability for sites with low security requirements to opt out of HPKP. > opt out?! It's off by default. I think tptacek meant that a site owner should be able to explicitly declare that nobody should be able to pin a key, so that nobody can hijack the site in the future.
- pfg 10y agoThat's an odd argument to make. You're essentially saying if you can't afford the most secure safe for your jewelry, just put it in a basket in front of your door instead of getting a cheaper safe that keeps most thieves out.
- jb613 10y agoBy suggesting HPKP is only for sites worried about nation state adversaries means deploying SSL without HPKP which leaves the door open for adversaries to get a cert issued for your domain.
- pfg 10y agoRight, I don't think you got my point. You don't always need the best option. CAs are far from perfect, but the threat model for a blog or a cat-sharing site is unlikely to include adversaries who are capable of compromising a CA (whether they're nation-state adversaries or not). SSL without HPKP is probably good enough for you in that case. Saying that the traditional CA system without HPKP is as bad as a plaintext protocol is silly.
- jb613 10y agoYou are underestimating 1) the number of CA's embedded in your browser, 2) how easy it is to get one of those CA's to issue a cert for someone else's domain.