Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>It's recommended to announce two keys via HPKP

It's not just recommended, it's required. HPKP can certainly lock you out of your own site if done wrong but there are safeguards against that. A shockingly high number of sites that try to use HPKP don't actually do anything at all because every browser out there ignores their HPKP headers because they're malformed in some way.



That you would even consider trying HPKP without running the SSLLabs server test or Hardenize against it (which would identify these defects) is also shocking in itself.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: