4 ms·
> Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust ancho
by mrbabbage 10y ago
> Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. “Data loss prevention” appliances, firewalls, content filters, and malware can use this feature to defeat the protections of key pinning.
https://www.chromium.org/Home/chromium-security/security-faq#TOC-How-does-key-pinning-interact-with-local-proxies-and-filters- https://www.chromium.org/Home/chromium-security/security-faq...
I can't remember what Firefox does in this situation
- tyingq 10y agoWow..That pretty much neuters the entire purpose.
- aseipp 10y agoExcept for the fact that HPKP actually works and has been working. The part that "does not work" -- which is actually a design issue -- is that it does not override private anchors. The real thing you seem to be upset about is that Chrome even allows you to MITM TLS connections at all at any level, whether or not the "actor" is your boss or a rogue adversary. It's debatable whether or not this is a good policy[1]. It's also a completely separate debate from whether HPKP is "neutered" or not. [1] Realistically, it mostly doesn't matter what you think, because here's what will usually happen: Chrome doesn't allow MITM. Your business then enforces a network policy that bans Chrome from all devices. The alternative browser still allows MITM, and you still have to use them, and thus it still happens to you and everyone else. The end.