Hacker News new | ask | show | jobs
by mike_d 1371 days ago
> I guess cert pinning isn't a thing on Browsers, yet?

Locally installed root certificates override HSTS. Some regulated industries like banking are legally obligated to unwrap all TLS traffic, so locally installed roots allow for that.