3 ms·
It should be noted that certificate pinning is only effective if you can trust the origin of the certificate at the time it is pinned. Imho google is only pushi
by casual_slacker 13y ago
It should be noted that certificate pinning is only effective if you can trust the origin of the certificate at the time it is pinned. Imho google is only pushing for something like this because of the Iran incident[0] where a hacker (possibly the Iranian government) coerced a Dutch CA into providing a compromised certificate for gmail. It won't do much for stopping the US government who is already in a position to coerce CAs before pinning is implemented.
0: http://www.computerworld.com/s/article/9219731/Hackers_spied_on_300_000_Iranians_using_fake_Google_certificate http://www.computerworld.com/s/article/9219731/Hackers_spied....