4 ms·
If you're confused as to why, this article was illuminating: https://scotthelme.co.uk/using-security-features-to-do-bad-things/ https://scotthelme.co.uk/using-s
by moosingin3space 8y ago
If you're confused as to why, this article was illuminating: https://scotthelme.co.uk/using-security-features-to-do-bad-things/ https://scotthelme.co.uk/using-security-features-to-do-bad-t...
- tptacek 8y agoHPKP was underdesigned; it was a protocol evolution of something Google was already doing semi-manually. There was a competing initiative inside Google --- certificate transparency --- and that won out. There's validity in the approach and I hope it comes back sometime, maybe with additional mechanism around managing pins.