Hacker News new | ask | show | jobs
by btmerr 2868 days ago
Cert pinning. EOL.
3 comments

If it's in the binary Simple ships I can take it or modify it to not need it. It's a huge pain in the ass, but it's not "hard."

And while I know I did a cert pin and you did a cert pin, not everyone does it (or does it bidirectionally). Nor is that the only way folks would get an API spec.

There are ways to work around cert pinning
Can be easily bypassed.