3 ms·
By suggesting HPKP is only for sites worried about nation state adversaries means deploying SSL without HPKP which leaves the door open for adversaries to get a
by jb613 10y ago
By suggesting HPKP is only for sites worried about nation state adversaries means deploying SSL without HPKP which leaves the door open for adversaries to get a cert issued for your domain.
- pfg 10y agoRight, I don't think you got my point. You don't always need the best option. CAs are far from perfect, but the threat model for a blog or a cat-sharing site is unlikely to include adversaries who are capable of compromising a CA (whether they're nation-state adversaries or not). SSL without HPKP is probably good enough for you in that case. Saying that the traditional CA system without HPKP is as bad as a plaintext protocol is silly.
- jb613 10y agoYou are underestimating 1) the number of CA's embedded in your browser, 2) how easy it is to get one of those CA's to issue a cert for someone else's domain.