2 ms·
HPKP, in its current shape, is difficult to justify even to larger companies. Presumably, those companies who do consider it determined that there is a non-sign
by ivanr 9y ago
HPKP, in its current shape, is difficult to justify even to larger companies. Presumably, those companies who do consider it determined that there is a non-significant risk that they would be attacked via fraudulent (but of course valid) certificates. Given that unimportant sites don't face that risk, there's no reason to use HPKP for them.