certificate pinning is already in Chrome, and I think ChannelID is coming soon (if not already).
ChannelID: http://tools.ietf.org/html/draft-balfanz-tls-channelid-00
certificate pinning is already in Chrome, and I think ChannelID is coming soon (if not already).
ChannelID: http://tools.ietf.org/html/draft-balfanz-tls-channelid-00
ChannelID seems to operate in the same fashion. The first connection from Client->Server is completely without any security, but further connections can be verified.
> There are four classes of attackers against which we consider our security guarantees: passive network attackers, active network attackers, active network attackers with misissued certificates and attackers in possession of the legitimate server's private key.
Basically (and this is just my understanding), it should mean a MITM cannot decode the encrypted stream even if he has the legitimate server's private key.
(Disclosure: I wrote that section of the draft.)
[1] https://code.google.com/p/chromium/issues/detail?id=136462#c...