3 ms·
You are confused. This is exactly what pinning defends against.
by infinity0 11y ago
You are confused. This is exactly what pinning defends against.
- cbr 11y agoSorry, no: Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. -- https://www.chromium.org/Home/chromium-security/security-faq#TOC-How-does-key-pinning-interact-with-local-proxies-and-filters- https://www.chromium.org/Home/chromium-security/security-faq...
- deleted 11y ago[deleted]
- mil0 11y agoHow would the telco get their Private Trust Anchor into the certificate store ? More social engineering, i suppose. At the app level though, a chain resolution like what you describe is not required.
- maaku 11y agoI'll give you a hint: they run customs.
- blazespin 11y agoWuh? Why not just ask the user to insert the cert?
- therein 11y agoThey COULD do that but they almost certainly aren't doing that. That's a tedious task that requires a lot of time and technically competent employees. Also we are talking about apps implementing certificate pinning. Not reading from the OS store etc., and therefore, I don't see Kazakhstan reverse engineering and patching executables.
- nathan_f77 11y agoThey will be telling citizens to install a "national security certificate". After they implement this, you won't be able to access the internet without it.
- tremon 11y agoHow does "Chrome does not perform pin validation" translate to "This is not what pinning defends against"? The fact that Chrome ships with a broken implementation does not imply the concept is broken.
- tripzilch 11y agoYou are right of course, but there are apparently a whole lot of people of the opinion that since Chrome was (one of the?) first apps implementing some sort of pinning, that this is de facto what certificate pinning "is". I don't really agree with that, but it's IMO more useful to acknowledge the confusion, than having an argument about whether Chrome really does pinning or even gets to de facto define pinning or not, since this isn't even about Chrome :)
- tremon 11y agoI get your point. The notion of designating a broken implementation as "the standard" makes me queasy, ever since IE6 happened. But still, I would have much preferred if the GP would have started their comment with "yes, but" instead of "sorry, no". That would have made the distinction much clearer.
- mtgx 11y agoWhy the hell doesn't Chrome have its own root cert store by now anyway? I can't believe they are leaving such an important trust piece to Microsoft's Windows...