Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Certificate pinning seems like extreme overkill for nearly all applications. Are most folks really doing this?


A regime can now force you to install their "root certificate" (and forcing organizations under their rule, e.g. national banks) to use a certificate issued by them, and these certificates would also be able to MITM your connection to e.g. Google. (1)

Looking forward to Americans being forced to install the DOGE-CA, X-CA or Truth-CA or whatever...

1) https://blog.mozilla.org/netpolicy/2020/12/18/kazakhstan-roo...




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: