3 ms·
Some clients use certificate pinning of known popular XMPP hosts. For example, ChatSecure (née GibberBot) on Android appears to use Moxie's certificate pinning
by lambda 13y ago
Some clients use certificate pinning of known popular XMPP hosts. For example, ChatSecure (née GibberBot) on Android appears to use Moxie's certificate pinning for cert chains of a few well-known Jabber servers (like Google and Facebook's), so you will get a warning if they ever start presenting you with new certificates from a different CA.
The implementation leaves a little to be desired; the way it's implemented, any of the CAs for any of the pinned organizations could issue certs that could MITM you, but that's still a lot less than the usual default list of CAs in the system trust store.
- dingaling 13y ago> appears to use Moxie's certificate pinning for cert chains Marlinspike and Perrin actually proposed TACK ( http://tack.io/draft.html http://tack.io/draft.html ) which requires changes to TLS. Certificate pinning is different ( simpler and less flexible ) and does not require protocol changes, the logic is held at the application level.