4 ms·
I'm not following you. The way pinning (specifically HPKP) works is that you're supposed to use a valid WebPKI certificate, so the initial connection works, and
by ekr____ 2y ago
I'm not following you. The way pinning (specifically HPKP) works is that you're supposed to use a valid WebPKI certificate, so the initial connection works, and then you send a header to pin that certificate (or more likely it's CA).
- blincoln 2y agoPinning in mobile apps/IoT is usually done the way the grandparent comment suggests. The fingerprint of the key is hard coded into the app somewhere,[1] so there's no initial connection without it. IMO, pinning only solves the corner case scenario where a public CA is compromised or issuing fake certs under the table. Everything else is make-the-blue-team-feel-good measures like trying to keep users from intercepting their own traffic, or actively owner-hostile effects like devices no longer working when the cert is rotated. I'm happy to see CloudFlare calling for it to be retired. [1] sometimes it's more DIY than that, where the code will require that the issuing cert have a particular string in its name, etc.
- csande17 2y agoWebPKI still has the "devices stop working if certs are rotated" problem, just on a longer timescale. If the user takes an old IoT device out of the box, and the auto-update server is using a newer root cert that wasn't trusted when the device first shipped, they'll have a bad time. Any solution to this requires something that basically looks like certificate pinning. You've gotta rely on your server provider to use a dwindling set of "trusted by the original device firmware and also still trusted now" root certs forever (which gets fun when all of those certs are mandated to expire), or you've gotta create some other mechanism to establish trust on software updates (delivering them via unencrypted HTTP and then verifying an OpenPGP signature is a common choice).
- aflukasz 2y agoAh, yes, I was wondering if you have meant HPKP. But then I checked it's deprecated in FF, removed in Chrome and was never present in Edge or Safari. At least according to Wikipedia. MDN mentions it as "obsolete". So it doesn't look like something usable in practice these days, right?