Security

RIP HPKP: Google abandons public key pinning

No home in Chrome


Google is abandoning a next-generation web crypto technology it initially championed.

HTTP Public Key Pinning (HPKP) is a standard that allows a host to instruct browsers to only accept certain public keys when communicating with it for a given period of time. While HPKP can offer a lot of protection, the technology was open to potential abuse by hackers or accidental lockout if sysadmins misapplied it, as previously reported on The Register.

In a blog post last week, Google's Chris Palmer announced plans to deprecate HPKP support by Chrome from May next year – when Chrome 67 is slated to be released to Stable – before removing it entirely at some as yet unspecified date.

Google introduced HPKP support for Chrome around two years ago back in September 2015. Edge and Safari have never supported HPKP and the removal of support by other browser software makers is not anticipated to cause any major upheavals.

"There is no compatibility risk; no website will stop working as a result of the removal of static or dynamic PKP," according to Palmer who goes on to suggest possible alternatives to HPKP. "To defend against certificate misissuance, web developers should use the Expect-CT header, including its reporting function. Expect-CT is safer than HPKP due to the flexibility it gives site operators to recover from any configuration errors, and due to the built-in support offered by a number of CAs.”

Security researchers including Scott Helme previously criticised the technology as too cumbersome for mainstream use even among security-conscious organisations. Ivan Ristic of SSL Labs argued that HPKP was problematic because it failed to include a recovery mechanism rather than being an inherently bad idea.

“Two HPKP disappointments. First, that a half-baked standard got deployed to production. Second, [the] decision to kill it, rather than fix it,” Ristic said in reaction to Google’s decision. ®

Send us news
9 Comments

Banned Nvidia GPUs sneak into sanction-busting Chinese servers

Graphics giant and partners say they're clean - it's all technically legit

Miles of optical fiber crafted aboard ISS marks manufacturing first

ZBLAN fibers made in space hopefully don't crystallize and are far less brittle, opening the path to faster photonics

Seagate joins the HDD price hike party, blames AI for spike in demand

Expect ongoing supply shortages this year, say storage analysts

SpaceX workplace injury rates are rocketing

Musk outfit's figures almost 10 times worse than industry averages

Miracle-WM tiling window manager for Mir hits 0.2.0

What are Mir and Wayland all about anyway?

GM shared our driving data with insurers without consent, lawsuit claims

Motorists file class action alleging breach of contract and more after their premiums went up

iPhone sales dive 19.1% in China as Huawei comeback hits Apple in the high end

From first place to third as local brands grow

Microsoft shrinks AI down to pocket size with Phi-3 Mini

Language model focused on reasoning fits on a smartphone and runs offline

Digital Realty wants to turn Irish datacenters into grid-stabilizing power jugglers

Electricity goes both ways as bit barns in Dublin aim to cut emissions and boost the bank

Microsoft really does not want Windows 11 running on ancient PCs

Even tighter requirements, so it's time to put old hardware out to pasture... or find an alternative OS

SAP cloud swells its topline, but profits slide

Cloud migration good for margins, CEO says

Mandiant: Orgs are detecting cybercriminals faster than ever

The 'big victory for the good guys' shouldn't be celebrated too much, though