Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, HSTS doesn't pin the cert, it just says that TLS must be used. A custom root certificate will fulfill that requirement.

Cert pinning isn't used by browsers in general.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: