Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, it doesn't. HSTS and other methods prevent this from happening.
 help



HSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine.

No mainstream browser (or any browser?) is doing cert pinning.

What "other methods" are there that are deployed and actually in use?


Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: