Reply to post: Pinning.

Confused by crypto? Here's what that password hashing stuff means in English

TeeCee Gold badge


So, in other words, pinning means: "We trust the following CA's, but not enough that we think they won't issue a bent cert purporting to be for our site. We need to check to ensure that the cert is from the right trusted CA...."?

If bent certs from trusted CA's is a real risk, then the word "trust" is being heavily misused by someone and fixing that, rather than sticking a layer of tape over the hole, is the right way to go.....

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon