Hacker News new | ask | show | jobs
by tprynn 623 days ago
I am. Pinning is a footgun with negligible real world security impact:

https://tprynn.github.io/2022/12/06/cert-pinning-bad.html

1 comments

A few thoughts:

1. Almost all mobile devices used by adults to access their work email have provisioning profiles that allow trusted certificates to be installed by one’s employer.

2. Plenty of authoritarian counties require trusting CAs operated by the government. If you have users in those countries, they are vulnerable to snooping.

Your blog post makes it seem like users vulnerable to MITM attacks are in the minority, when in fact they are likely in the vast majority.