Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Too many people have foot-gunned themselves with that one. As someone who has to readily fight technical fires for other people (when they should have googled their problems) I am glad to see HPKP go.


Honestly there are a lot of ways for people to foot-gun themselves when dealing with providing a service. HPKP isn't perfect, but deprecating it just for the sake of keeping some incompetent people safe is just silly. Might as well remove HSTS and not roll out Expect-CT because everything allows someone to foot-gun themselves.


The difference between HSTS, Expect-CT and HPKP is that the former two offer a way out (support HTTPS, provide qualified SCTs) whereas HPKP can effectively brick your domain for a couple of months, and it's not even hard to pull off.


HPKP can brick your domain if you use HSTS alongside with it, if you don't then one can fall back to http. Not an ideal solution, but it's a way out. HSTS is an extreme and possibly dangerous measure that should be carefully considered (maybe it shouldn't be TOFU but TOTU - trust on third use), but I still think it's not reasonable to totally deprecate it. There are cases where such measure would provide clear and strong security benefits.


That sounds nice and all but you don't have to support it




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: