3 ms·
> which some folk were wishing might have existed for SSL certificates the other day Isn't this basically what HSTS + cert pinning does?
by cheald 5y ago
> which some folk were wishing might have existed for SSL certificates the other day
Isn't this basically what HSTS + cert pinning does?
- BeefWellington 5y agoCert Pinning is more akin to "trust on zeroth use, only this certificate", HSTS is kind of unrelated since all it does it tell the browser to access the site via HTTPS. If the site is on the preload list all that buys you is the first access must be over TLS. Pinning is more for the app case, HSTS more for the browser case.
- andrewaylett 5y agoHSTS and pinning (which isn't used on web any more, because it's too much of a foot-gun) help you be sure that you're really talking to who your computer thinks you're talking to. A password manager (or, better WebAuthn) helps you be sure you're talking to the same site that you were talking to when you set up your account. If you're on the wrong site, all the validity indicators in the world won't help the misidentification. And it needn't even be a malicious site: I auto-fill my work credentials in part so that I don't have to remember which internal tools take which set of credentials. Which isn't nearly as much of an issue nowadays (with more SSO) as it was a few years ago, but that just makes the last few exceptions all the more difficult to remember.