Didn't mean to offend. We consider ourselves nerds, and mean it affectionately.
And I will accept your sarcastic congratulations on "basic" SSL best practices with pride. I think you'll find that HPKP implementations are currently still very rare, and I do not consider it "basic".
That's cool, I'll get over it! I still don't really like the word "nerd", but to be fair, I did struggle to come up with a better title.
And sorry for the sarcasm, it does look like you're doing everything right.
When you say almost all your software is written in Go, is that including the telecom stack? I just didn't think Go was ready to compete with the Erlang VM in that arena.
It doesn't bother me but will bother some as we see. Maybe techie or something that's fairly neutral? Geek doesn't have nerd's negative connotations as much and is becoming mainstream. Probably something to use other than nerds in the label to show you're technical people helping technical people without offending anyone who hate that one label.
HPKP is indeed quite rare. But I am very worried to see that you are pinning end-entity keys and have only a single backup pin. If you want to pin end-entity keys, I recommend pinning at least three backup keys, using both RSA and ECDSA of varying key sizes. You have to be very concerned with bricking your site from either losing your backup keys, or CAs/browsers rejecting your backup keys because cryptographic standards have changed. Pinning end-entity keys is not for the faint-hearted.
And I will accept your sarcastic congratulations on "basic" SSL best practices with pride. I think you'll find that HPKP implementations are currently still very rare, and I do not consider it "basic".