Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> eventually, hopefully, I'll disallow websites that don't have HPKP with long expires

I doubt HPKP will ever see wide adoption. At least not in the form it has now. It's just too damn easy to bork the config and take your entire site offline with no way to remedy that error.



Not really. Just put a root level cert or two as your backups.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: