3 ms·
Well, requiring a WebPKI valid certificate itself prevents MITM attacks. What pinning does is prevent MITM attacks in the case where the attacker has a valid (b
by ekr____ 2y ago
Well, requiring a WebPKI valid certificate itself prevents MITM attacks. What pinning does is prevent MITM attacks in the case where the attacker has a valid (but misissued) certificate.
It's true that CT doesn't prevent this class of attack; instead what it does is require that valid certificates be public, thus -- at least in principle -- allowing for detection of misissuance.
- patrakov 2y agoNot really true. Please also consider the case where the user and the attacker are one and the same person trying to reverse-engineer your mobile API. Then the certificate is misissued from the viewpoint of the app developer but not from the user's viewpoint.