Hi Dwarden,
comments in-line.

Yes, don’t currently support HPKP. We are still investigating the best way to support that. I was also trying to find a good source of information about the adoption of HPKP at present? Would you guys have any resource about the percentage of pages supporting HPKP?

We intend to add OCSP stapling support, the implementation is already finished in the internal version and will be released with the next avast version (probably Avast 2015 R3). Please note that we do support OCSP and CRL checks.

This is surprising to me that this is considered as a negative by some. We don’t scan EV certificates, the fact that a certificate is evaluated as EV is a trigger for us to trust the connection and do not interfere with it. It is by design and disabling this is very easy. There is a INI option for that. Detecting an EV cert and correctly ignore such connections from the scan is fairly difficult, yet we though users would value this effort. If the bank (or other company) on the other side of the connection has already verified its identity enough for the CA to issue an EV certificate to it, we wanted to keep the connection private.

Truth is that even EV signed connection can lead to hacked pages, but it is always about balance and for us this was the limit we chose.

Would you like to have every connection to go via WebShield’s scanning? Even EV ones?

Lukas.