|
|
|
|
|
by dagenix
2845 days ago
|
|
> That's exactly the same situation as any other TLS failure, not at all unique to HPKP in any way that I'm seeing. Yup. But the feeling I'm getting is that browser vendors see this behavior as non-ideal since it trains users basically ignore the error. Yeah, in theory the user gets to make their own decision. My theory is that almost no user is actually equipped to make such a decision. > admins of bricked sites can give them guidance that doesn't involve following convoluted instructions to navigate about:config or chrome://net-internals. I see this as a worst case outcome - explicitly telling users its ok to bypass a security warning. > All you need is to back up the spare key somewhere without throwing it out, which is a minor annoyance but not at all technically difficult. Not technically hard, but still plenty of ways to mess it up. And once it's messed up, there isn't much of a good way to fix it. |
|