Hacker News new | ask | show | jobs
by darklajid 3512 days ago
Your point isn't bad, you just ignored/overlooked the 'expiring' part of the announcement.

If you don't pay for the renewal, pinning _probably_ is broken anyway (unless you somehow pin a cert, but ignore validation. In which case you should've used a self-signed cert from the start, I guess).

Honestly, I cannot see a downside to this. People that won't pay the CA mafia will get a cert for free. TLS everywhere. The internet wins.