Hacker News new | ask | show | jobs
by throwaway2016a 453 days ago
You contradict your part here. I'm not sure if you meant to because the rest of your post sounds like it is saying Mozilla needs to pin if it's using a custom signing mechanism.

> Firefox uses (and ships with) the Mozilla Root Program

> can not not pin certificates

Shipping with a certificate store is by definition, pinning. So not only can it but your own post states it is when it says "and ships with".