Closed Bug 1684787 Opened 5 years ago Closed 5 years ago

Add support for HTTP Public Key Pinning (HPKP)

Categories

(Core :: Security: PSM, enhancement)

enhancement

Tracking

()

RESOLVED WONTFIX

People

(Reporter: u677327, Unassigned)

Details

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0

Steps to reproduce:

HTTP Public Key Pinning (HPKP) dramatically increases security of connections and should be added and apply only to EV certificates.

I'm aware that it was previously removed for the unlikely and well known before standardization risk of ransom as recommend by Google who provided a centralized PRISM surveillance replacement called Certificate Transparency, but only applying EV certificates makes ransom extremely unlikely.

It may be a coincidence but Google's recommendation came at a time when the NSA's PRISM program was losing real-time OCSP data from the adoption of certificate stapling and their Certificate Transparency solution once again provided PRISM with the data that they were losing.

Certificate Transparency is records of certificates but browsers shouldn't be connecting to PRISM providers when decentralized solutions like HPKP exist.

HPKP should be added for EV certificates and remote Certificate Transparency functions should be disabled if HPKP is in use.

Bugbug thinks this bug should belong to this component, but please revert this change in case of error.

Component: Untriaged → Security: PSM
Product: Firefox → Core

Chrome certainly won't do this, so web sites are unlikely to use HPKP (adoption was never high, even when Chrome did support it). For sites that do use it, Firefox users will simply use another browser when they see an error page. So, this offers no practical benefit for the considerable risk it poses.

Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.