<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>certificate-pinning on {bjørn:johansen}</title>
    <link>https://bjornjohansen.com/tag/certificate-pinning/</link>
    <description>Recent content in certificate-pinning on {bjørn:johansen}</description>
    <generator>Hugo -- 0.118.2</generator>
    <language>en-US</language>
    <lastBuildDate>Thu, 16 Jul 2015 11:39:19 +0000</lastBuildDate>
    <atom:link href="https://bjornjohansen.com/tag/certificate-pinning/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTTP Public Key Pinning (HPKP)</title>
      <link>https://bjornjohansen.com/public-key-pinning/</link>
      <pubDate>Thu, 16 Jul 2015 11:39:19 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:36656436-3236-5036-a238-646136336161</guid> 
      <description>&lt;a href=&#34;https://www.bjornjohansen.com/securing-nginx-ssl&#34;&gt;Using HTTPS&lt;/a&gt; helps preventing someone from snooping your username/password or hijacking your sessions. &lt;a href=&#34;https://www.bjornjohansen.com/optimizing-https-nginx&#34;&gt;Using HSTS&lt;/a&gt; makes sure the connection stays on HTTPS, even if a MITM tries to redirect you to the plain HTTP version of a web site. But it is easier than you might think for a MITM to use a rogue certificate, making you believe everything is fine. HTTP Public Key Pinning (HPKP) helps the browser check that everything actually is fine.</description>
    </item>
  </channel>
</rss>
