Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there any reason that pinning should not be optional?

In other words, any reason that the user should not be able to "disable" it? (Use own root CA.)

Consider that in this case, the data being transferred to Facebook belongs to the user.

Is it unreasonable for a user to require that they be able to see what data is being transferred before they agree to transfer it?



Enterprises do this on PC --- they have to be able to MITM all their user's traffic. Not sure how mobile devices are covered.

As for transparency, look to GDPR and friends to see what rights are being declared.


Considering that certificate pinning protects hacked user devices from making insecure communications, it would completely defeat the point if the user could disable it.


I don't think so. Certificate pinning protects from rouge CAs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: