Insecure web still too prevalent: Boffins unveil HSTS wall of shame


You mean that certificate pinning which is already on the way out again (deprecated in Chrome) before it's even fully arrived (no support in Edge yet), because between short-lived certs and spare private keys, you actually need some amount of planning to deploy it reliably?

