Hacker News new | ask | show | jobs
by Tergmap 3576 days ago
He says "bricking your website" while he means "your website will appear as if it has an invalid certificate".

Bricking means to crash something beyond repair.

2 comments

No, when HPKP breaks your site no longer works, period. The error page doesn't allow clicking through. Some browsers (e.g., Chrome) support manual editing of the HPKP configuration so some users might be able to get around the problem, but that's unlikely to work for many.

Try it here: https://pinning-test.badssl.com

Most users won't click through on a prompt that a website is insecure though. For that majority of users the website is well and truly "broken beyond repair".

The only thing that matters is what your users experience, not what your server serves.