Actually WebSign is still in production at Cyph, and never strictly depended on HPKP, with the caveats that:
1. Rather than simply prevent an attack, it shows a scary warning that compromised code will be run on the next reload, and
2. It relies on things that aren't intended as security features, and so is inherently more fragile than it was originally. In particular, if an attacker could fill up enough of a user's disk space, some browsers may just evict the WebSign instance.
We recommend that regular users of Cyph install the desktop and mobile apps, but it's at least a reasonably safe solution that significantly improves usability.
1. Rather than simply prevent an attack, it shows a scary warning that compromised code will be run on the next reload, and
2. It relies on things that aren't intended as security features, and so is inherently more fragile than it was originally. In particular, if an attacker could fill up enough of a user's disk space, some browsers may just evict the WebSign instance.
We recommend that regular users of Cyph install the desktop and mobile apps, but it's at least a reasonably safe solution that significantly improves usability.