-
@bagder @PCTuning_OW @jpmens No there is no. "per se" short renew may be better in case of not seen compromission […]
-
@bagder @PCTuning_OW @jpmens […] because in this case, you need to redo compromission ever and ever, and raise probability to be seen. […]
-
@bagder @PCTuning_OW @jpmens […] But with overall X.509/TLS ecosystem (DANE, HSTS, HPKP, OCSP stapling…), shortening cert renew is worse.
-
@bagder @PCTuning_OW @jpmens Typically in HPKP, the time between a HPKP change and first HPKP expiration is critical […]
-
@bagder @PCTuning_OW @jpmens You have no choice in case of compromission during this period : you need to keep compromised material online.
-
@bagder @PCTuning_OW @jpmens If you renew key each 90d with recommended 60d HPKP expiration, you only have 30d of real security…
aeris22’s Twitter Archive—№ 25,058