Should we enable HTTP Public Key Pinning (HPKP) for whonix.org?

Information

ID: 84
PHID: PHID-TASK-apzzbas3sha4zupc73hk
Author: Patrick
Status at Migration Time: wontfix
Priority at Migration Time: Normal

Description

This has a high potential of DDOSing ourselves.

common pitfalls:

__If__ we ever go for HPKP, we need to test it on a separate test-only domain first (and perhaps even on a separate server).

Related:
T86

Comments


marmarek

2017-11-09 16:38:57 UTC


Patrick

2018-07-09 05:21:13 UTC