3 ms·
The fact you not once in your reply acknowledge that certificate pinning and bundling trusted root CA public keys is actually common knowledge in desktop and mo
by throwaway2016a 2y ago
The fact you not once in your reply acknowledge that certificate pinning and bundling trusted root CA public keys is actually common knowledge in desktop and mobile app community makes me thing you didn't even consider my reply.
I was simply explaining why for a desktop app pulling down the new certificate doesn't make sense because updating an app to update the pinned certificates is SOP for apps that use pinning.
> A strawman argument is where you attack a lesser flawed argument than what was said with the implication or claim that it is the same as the first. This wasn't a strawman argument, it was about exactly what was said despite the gymnastics needed to parse your statements.
No it literally was not. It was so much not what I said I wonder if you are replying to a completely different post. And rather than acknowledge you may have misinterpreted me, you are doubling down.
Also, that definition of straw man is wrong. It can also be -- as it is in this case -- attacking an argument the person never even made in the hopes it will bring the debate onto your terms.
But, I'm not attacking the straw man back, once again, at no point did I advocate for certificate pinning in open source apps nor make any comment on GPL or Mozilla.
My post was simply a statement on how to update apps that use certificate pinning. Reading any more into it than that is you injecting context that is not there.
Have a good day. My post is net positive votes now. I will not be replying to this conversation further.
- nofunsir 2y agoCite your sources, please. So far you're incorrect.
- throwaway2016a 2y agorolls eyes sure bud Tell me, how exactly else are you supposed to update an app with a pinned certificate without defeating the whole purpose of pinning? How about Google? https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store/faq.md https://chromium.googlesource.com/chromium/src/+/main/net/da... > The Chrome Root Store contains the set of certificates Chrome trusts by default. Google also bundles some certificate fingerprints with their browser. You can see right here where they are in their source code: https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store https://chromium.googlesource.com/chromium/src/+/main/net/da... But according to trod1234 it is "common knowledge" you shouldn't do that... so Google and Mozilla must both be idiots. In fact, Google's Android network article has a section specifically on how to add it to their mobile apps[1]. Any app that follows that article and has a root key expire will need to push an update if they don't have backup pins. And the only way to do that is... as I said in my original reply up top... update the entire app the cert is pinned too. There are literally hundreds of sources I can find. Including the other reply to the post I replied to... which says the same thing as me but for some reason isn't being trolled. [1] https://developer.android.com/privacy-and-security/security-config#CertificatePinning https://developer.android.com/privacy-and-security/security-...
- trod1234 2y agoThe links you provide do not properly support what you say, imply, or claim. The three links I provide below contradict the claims that are objectively discern-able. The rest is ignored. What I actually said is common knowledge in the field and best practice, more importantly its not just me saying it; it is well known in industry, see [1][2][3]. There is no need for any further correspondence here. [1] https://www.ssl.com/blogs/what-is-certificate-pinning/ https://www.ssl.com/blogs/what-is-certificate-pinning/ [2] https://blog.cloudflare.com/why-certificate-pinning-is-outdated/ https://blog.cloudflare.com/why-certificate-pinning-is-outda... [3] https://developer.android.com/privacy-and-security/security-ssl https://developer.android.com/privacy-and-security/security-... (Restricting your App to Specific Certificates... Caution...)
- nolist_policy 2y agoYour links apply to public pki certificates. Now, I didn't read the source code, but Mozillas wording implies they use a custom pki to sign extentions. Given that most (all?) root programs only certify host names or email addresses (S/MIME), it is reasonable for Mozilla to run a custom pki for this. And that neccesarily requires shipping/pinning the root certificates. Actually this whole discussion is moot, because Firefox uses (and ships with) the Mozilla Root Program. So it can not not pin certificates, because that is the whole point of a root program. Looks like we all learned something today.
- deleted 2y ago[deleted]
- throwaway2016a 2y agoYou contradict your part here. I'm not sure if you meant to because the rest of your post sounds like it is saying Mozilla needs to pin if it's using a custom signing mechanism. > Firefox uses (and ships with) the Mozilla Root Program > can not not pin certificates Shipping with a certificate store is by definition, pinning. So not only can it but your own post states it is when it says "and ships with".
- 2y ago