Re: [websec] Pre-loaded pins vs dynamic pins

2014-02-19 Thread Daniel Veditz
On 2/19/2014 1:13 PM, Chris Palmer wrote: On Thu, Feb 13, 2014 at 11:42 AM, Trevor Perrin wrote: Your "fourth way" is well-put, and I agree - all of these seem valid implementations which should be allowed. I have been thinking that this 4th way is the way to go. Note for example that RFC 67

Re: [websec] Consensus call: Issue #57 (max-max-age)

2013-05-22 Thread Daniel Veditz
On 5/22/2013 3:29 PM, Trevor Perrin wrote: The draft discusses "Preloaded Pin Lists", which are presumably conveyed to the UA from some 3rd party (eg browser vendor). It seems reasonable for such lists to be created or kept fresh by scanning web sites. I believe Mozilla is taking this approach