Skip to content
This repository has been archived by the owner on Jul 11, 2023. It is now read-only.

Certificate Pinning #439

Closed
JumaBok opened this issue Jun 14, 2022 · 1 comment
Closed

Certificate Pinning #439

JumaBok opened this issue Jun 14, 2022 · 1 comment

Comments

@JumaBok
Copy link

JumaBok commented Jun 14, 2022

Genuine question on this one - but is pinning not considered an obsolete / bad practice today? I'm by no means a security expert but it was my impression that this causes more issues than it solves, and has since been essentially abandoned. Just noticed this when reviewing your security documentation (as a form of basic checklist if anything)...

I may be wrong!

Some references I've reviewed:

https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning
https://cheapsslsecurity.com/p/what-is-http-public-key-pinning-and-why-its-not-good/
https://developer.mozilla.org/en-US/docs/Web/HTTP/Public_Key_Pinning

Maybe I'm getting confused with two different approaches.

Thanks

@jcesarmobile
Copy link
Member

closing since latest docs don't mention anything about certificate pinning

@jcesarmobile jcesarmobile closed this as not planned Won't fix, can't repro, duplicate, stale Aug 25, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants