I’ve heard multiple times that “certificate pinning is obsolete.” Who is pushing this narrative?
I’ve heard multiple times that “certificate pinning is obsolete.” Who is pushing this narrative?
It's true that CT doesn't prevent this class of attack; instead what it does is require that valid certificates be public, thus -- at least in principle -- allowing for detection of misissuance.
1. Almost all mobile devices used by adults to access their work email have provisioning profiles that allow trusted certificates to be installed by one’s employer.
2. Plenty of authoritarian counties require trusting CAs operated by the government. If you have users in those countries, they are vulnerable to snooping.
Your blog post makes it seem like users vulnerable to MITM attacks are in the minority, when in fact they are likely in the vast majority.