4 ms·
In April next year we will have the CT requirement for all certificates so EV will lose an edge there. For the pinning in a mobile app, would you still depend
by Scott_Helme_ 9y ago
In April next year we will have the CT requirement for all certificates so EV will lose an edge there.
For the pinning in a mobile app, would you still depend on the PKI or not just pin against your own private CA/certificates?
- BillinghamJ 9y agoOur mobile apps use the same endpoints/hostnames as our public API, so fairly important for it to be publicly trusted. I do still think the barrier to entry aspect of EVs will always be very helpful. In a world where you can get a DV cert in under a second (from LetsEncrypt), if your DNS or domain registration was to be compromised, you’d have no MITM protection at all until you managed to get it revoked - which is likely to take days. It’d almost be helpful to have a system where certs have to be requested (publicly on CT records) a week in advance or something, so issuance can be protested if something like the above did happen.