3 ms·
> Simplest way would be to embed public key in the application Yes, but one eventually faces the need to update the certificate on the server, and still suppor
by groue 10y ago
> Simplest way would be to embed public key in the application
Yes, but one eventually faces the need to update the certificate on the server, and still support installed applications (which fails when apps have an obsolete certificate pinned). Hence the need for smooth certificate updates, and the good smell of HPKP. But it addresses another need, hence my confusion.