Tag: HPKP

Neutralizing and protecting against rogue TLS certificates in the wild

August 17, 2017

Techniques for fighting mis-issuance of TLS certificates The web has reached the tipping point where encrypted traffic – connections protected by HTTPS, which is HTTP over SSL/TLS – has overtaken unencrypted (HTTP) traffic. There are many reasons for this change, variously called HTTPS Everywhere or Always-On SSL, which we described in a previous FYI blog […]