3 ms·
In this case, if understand the concept correctly, it would be iTunes that pins the certificate authority for the iTunes server. One would still be vulnerable
by markild 14y ago
In this case, if understand the concept correctly, it would be iTunes that pins the certificate authority for the iTunes server.
One would still be vulnerable of a corrupt CA. The only solution to this would be to issue all certificates from an internal CA and verify this in your application.
- StavrosK 14y agoOr you could just harcode the certificate fingerprint and refuse to accept anything else. It's trivial when you own the client. I'm not sure if this would break when you needed to renew the certificate, but I guess you only update the signature, not the actual public key.
- phillmv 14y agoWhen you ship your own browser and OS you can prob get away with that.