4 ms·
I wish that modern browsers made it possible to trust a CA certificate only for specific sites, or to pin the one used in a specific site so other CAs can't be
by snakeanus 9y ago
I wish that modern browsers made it possible to trust a CA certificate only for specific sites, or to pin the one used in a specific site so other CAs can't be used silently.
I also wish that more browsers supported OpenPGP certificates instead, as it is a simpler while at the same time more powerful format (allows for multiple signatures for example).
- thefifthsetpin 9y agoHSTS already protects you from attackers that get another CA to sign their certificate. There would be obvious problems with encouraging you as a user manage pinning (how would you know whether a site will deviate from what you pinned?) If you understand that but want to pin as a user anyway, chrome will let you do that: chrome://net-internals/#hsts
- snakeanus 9y ago>chrome will let you do that: chrome://net-internals/#hsts Aren't the hashes there only for the public keys of the site instead of the public key of the CA? Also, does anybody happens to know any extension for Firefox that does anything similar to that?
- wolfgang42 9y agoI think that's HPKP you're thinking of; HSTS only declares that the site plans to continue requiring HTTPS without specifying a CA or public key that it will use.