Certificate pinning

Post here your questions about SFS2X. Here we discuss all server-side matters. For client API questions see the dedicated forums.

Moderators: Lapo, Bax

miv
Posts: 8
Joined: 16 Jun 2014, 08:10

Certificate pinning

Postby miv » 02 May 2017, 13:15

Hello! Is there a way to pin certificate/pk used for encryption negotiation[1]? So no malware can just set self-singed cert as "allowed" on user's system and snoop all https traffic.


[1]: https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning
User avatar
Lapo
Site Admin
Posts: 23026
Joined: 21 Mar 2005, 09:50
Location: Italy

Re: Certificate pinning

Postby Lapo » 02 May 2017, 14:16

Hi,
I understand the "key pinning" issue and I don't think this is supported in any of the client side languages.
We base the security of the process and API provided by each platform, e.g. .Net or Java, so unless they provide a native support for key-pinning, I don't it's feasible.

So no malware can just set self-singed cert as "allowed" on user's system and snoop all https traffic.

This part I don't get.
The certificate is on the server side, not the client. So I am not sure what malware are we talking about. If a malware gets installed on a server it's always bad, regardless of what kind of attack it performs...

cheers
Lapo
--
gotoAndPlay()
...addicted to flash games

Return to “SFS2X Questions”

Who is online

Users browsing this forum: Alexwek and 62 guests