3 ms·
The article mentions certificate pinning is used to prevent MITM attacks, but none of the alternatives listed actually prevent this class of attacks. I’ve hear
by njtransit 2y ago
The article mentions certificate pinning is used to prevent MITM attacks, but none of the alternatives listed actually prevent this class of attacks.
I’ve heard multiple times that “certificate pinning is obsolete.” Who is pushing this narrative?
- ekr____ 2y agoWell, requiring a WebPKI valid certificate itself prevents MITM attacks. What pinning does is prevent MITM attacks in the case where the attacker has a valid (but misissued) certificate. It's true that CT doesn't prevent this class of attack; instead what it does is require that valid certificates be public, thus -- at least in principle -- allowing for detection of misissuance.
- patrakov 2y agoNot really true. Please also consider the case where the user and the attacker are one and the same person trying to reverse-engineer your mobile API. Then the certificate is misissued from the viewpoint of the app developer but not from the user's viewpoint.
- tprynn 2y agoI am. Pinning is a footgun with negligible real world security impact: https://tprynn.github.io/2022/12/06/cert-pinning-bad.html https://tprynn.github.io/2022/12/06/cert-pinning-bad.html
- njtransit 2y agoA few thoughts: 1. Almost all mobile devices used by adults to access their work email have provisioning profiles that allow trusted certificates to be installed by one’s employer. 2. Plenty of authoritarian counties require trusting CAs operated by the government. If you have users in those countries, they are vulnerable to snooping. Your blog post makes it seem like users vulnerable to MITM attacks are in the minority, when in fact they are likely in the vast majority.