4 ms·
hmm, certificate pinning will not allow this gov-ca to work for a lot of high profile web sites. i wonder if these sites with cert pins are whitelisted by the k
by altmind 7y ago
hmm, certificate pinning will not allow this gov-ca to work for a lot of high profile web sites. i wonder if these sites with cert pins are whitelisted by the kz gov?
--
somehow i missed that HPKP is dead and will be removed from chromium and all the derivative browsers. now google is focusing on Expect-CT
- lpellis 7y agoMy understanding is pinning will not block this, locally installed trust anchors bypass pinning. https://groups.google.com/d/msg/mozilla.dev.security.policy/wnuKAhACo3E/cbxRVMkxDwAJ https://groups.google.com/d/msg/mozilla.dev.security.policy/...
- vbezhenar 7y agoThat's correct, HPKP does not block this. If some application uses manual pinning, it'll work (or, rather, won't work at all).
- kccqzy 7y agoAlthough pinned certificates have gone out of favor on the web, they are still very frequently used by iOS and Android apps. Last time I checked, the Facebook Messenger app refused to work when being MitM'ed.
- ralphm 7y agoI hope they pin on the key, not the certificate. For a mobile app I worked on, I had it pin the public key on the leaf certificate and indeed it would fail to connect in this scenario.