490 karma · joined April 18, 2020
HPKP was deprecated because it was too dangerous to be deployed in production.
Luckily the loop hole is being closed by the Polish authorities after it became popular.
There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
Yeah the checkmark is a Google idea, the BIMI standard is only about verifying the logo.
> Another issue, is that logos are much more volatile than domain names, and I don't see a good way to prevent scammers to bimi-register visually confusing logos. So I don't think it's a good idea to emphasize logos to users as a mark of trust in emails.
Well in theory the CA will manually verify that the logo submitted by the company is visually matching a registered trademark by the same company. That's the reason why a VMC certificate is so expensive. But let's see how it goes about that.