4 ms·
Um... certificate pinning? Fortunately, my last caveat covers a bunch of these. Also, I think you(I) forgot: * You are in fact hallucinating at this very mom
by jbclements 12y ago
Um... certificate pinning?
Fortunately, my last caveat covers a bunch of these.
Also, I think you(I) forgot:
* You are in fact hallucinating at this very moment.
- nullc 12y ago:) Cert pinning does nothing when the page is plain http as it is here. (and HTTPS's helpfulness is limited without HSTS; were it HTTPS I'd have a couple of other assumptions like none of the hundreds of CAs are malicious, and "no attacker is able to MITM between the site and any CA that does domain-validation.) I didn't run off that list to criticize the site. The last bullet is indeed good. :)