Navigation Menu

Skip to content
This repository has been archived by the owner on Nov 1, 2022. It is now read-only.

Fretboard: Certificate pinning #433

Closed
pocmo opened this issue Jul 17, 2018 · 1 comment
Closed

Fretboard: Certificate pinning #433

pocmo opened this issue Jul 17, 2018 · 1 comment
Labels
🌟 feature New functionality and improvements

Comments

@pocmo
Copy link
Contributor

pocmo commented Jul 17, 2018

From mozilla-mobile/fretboard#15

In addition to verifying the signature of a collection (#13) we should use certificate pinning:

https://www.owasp.org/index.php/Certificate_and_Public_Key_Pinning#What_Is_Pinning.3F
Fennec bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1329721

┆Issue is synchronized with this Jira Task

@pocmo pocmo added 🌟 feature New functionality and improvements <fretboard> labels Jul 17, 2018
@pocmo pocmo changed the title Certificate pinning Fretboard: Certificate pinning Jul 17, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Jul 18, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Jul 18, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Jul 26, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Jul 26, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Aug 7, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Aug 7, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Aug 8, 2018
fercarcedo added a commit to fercarcedo/android-components that referenced this issue Aug 8, 2018
@pocmo
Copy link
Contributor Author

pocmo commented Aug 21, 2018

WONTFIX: Given the feedback of the security team I think we should move forward without certificate pinning. Signature validation is a stronger signal and does not have all the problems that come with cert pinning.

@pocmo pocmo closed this as completed Aug 21, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
🌟 feature New functionality and improvements
Projects
None yet
Development

No branches or pull requests

1 participant