Post
Topic
Board Bitcoin Discussion
Re: Mt Gox Break In Part 2
by
mrb
on 13/09/2011, 08:24:45 UTC
Mozilla is considering pinning keys on first site access. So the only way to MITM false certs is during the first access (which makes it same to ssh's flaw on server fingerprint (aka ~/.ssh/known_hosts)).

I would love it  Kiss The only way to provide this sort of pinning with any browser is to delete all trusted CAs before browsing any HTTPS site.