5 ms·
We're also using an EV cert for pinning in our native apps (in other words, we're not pinning a public key or a CA, but the fact that the certificate is an EV c
by markonen 8y ago
We're also using an EV cert for pinning in our native apps (in other words, we're not pinning a public key or a CA, but the fact that the certificate is an EV cert), on the theory that this is less risky operationally than pinning any specific details of an actual certificate. We can get a new certificate from a bunch of CAs, but it's tricky for an attacker to get one for our domain name. (no need to reply to this with stripe.ian.sh)
However, now that EV certs are clearly going the way of the dodo, the risks associated with them are likely to increase. CAs are going to be exiting the EV business (and/or going out of business themselves). The dwindling market is also likely to increase the price of an EV cert, rather than decrease it, as remaining purchasers will have a specific need to use an EV cert.
It might be time to re-evaluate.
- BillinghamJ 8y agoI don’t think they’re actually likely to go away for many years. The CA/B forum may decide to deprecate them one day though.