Hacker News new | ask | show | jobs
by pfg 3354 days ago
Yes, this is exactly the thing that HPKP would prevent from happening.
1 comments

Not supported in IE or Edge though, right? So it would still catch some end users.

Banrisol currently has a message up on their home banking portal that Firefox isn't supported.

That's right, they don't have a pinning mechanism for site operators. They have something called Certificate Reputation[1] which works alongside SmartScreen and should theoretically be of use for attacks like this, but I haven't heard much about it and I don't know if it helped here.

[1]: https://blogs.msdn.microsoft.com/ie/2014/03/10/certificate-r...