← Back to release summary

Remove HTTP-Based Public Key Pinning

Category
Security
Type
New or changed feature
Status
Removed (Chrome 72)
Intent stage
None

Summary

HTTP-Based Public Key Pinning (HPKP) was intended to allow websites to send an HTTP header that pins one or more of the public keys present in the site's certificate chain. It has very low adoption, and although it provides security against certificate misissuance, it also creates risks of denial of service and hostile pinning. See https://groups.google.com/a/chromium.org/d/msg/blink-dev/he9tr7p3rZ8/eNMwKPmUBAAJ for details.

Standards & signals

View on chromestatus.com