Conversation

TIL: if you want TLS downgrade protection, you MUST only use one of the DHE or ECDH key exchange algorithms. Others like DH_RSA do not sign the random bytes in Hello messages used to prevent TLS downgrade attacks.
1
3
Replying to and
Sadly, Google is phasing out HPKP and others are likely to follow. I'll still set it even if all mainstream browsers drop it since at least it communicates intent. CAA isn't retroactive so it doesn't do much. Can still use TLS pinning in apps either way: github.com/AndroidHardeni