Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



I don't use either of those as http clients in my idiotic hobby projects that lookup DNS over TLS/HTTP.



Independent of HPKP Chrome still does 2011-style static pinning AFAIK and just by looking at HTTP headers I don't think google.com even uses HPKP. Unlike HPKP which is trust-on-first-use, static pinning is enforced from the very start so if you have the ability to statically pin in the client (as you would if you're a browser vendor or distributing your own mobile app) you probably should.

And then there is this recent discussion: https://news.ycombinator.com/item?id=12434585




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: