As part of the TLS handshake, a client could request a compliant TACK server to send its TSK public key and signature. Once a client has seen the same hostname-TSK pair multiple times, it could decide to activate a time-limited
pin for that pair. By time-limiting the pins, the potential impact of a bad pinning decision is
bounded. The specification also mentions that pins could be aggregated and shared through a
trusted third party but without defining either the infrastructure or the protocols required. This
proposal, while promising, is still in a very early stage and accordingly not suitable for use in
a production environment.