41 karma · joined May 1, 2018
I've worked on a team that reverse engineered and did security audits on a lot of commercial and consumer applications. We've seen cert pinning implemented correctly was maybe like once or twice a year by companies large enough to where their security team was larger than most software companies entire payroll.
Basically, it's not a thing that exist because it is really hard to implement properly. The threat model for being MITM'ed with cert spoofing is pretty exotic. In the end, cert pinning means your application is not working if something goes wrong with the certs, which EVERYONE at some point forgets to renew, or, worse, you CA inadvertently gets hosed.
We are MindForge, a division of the International Risk Management Institute. We create and publish interactive training that aims to give construction workers the mental tools they need to survive the day to day hazards they encounter on job sites. We are creatives, game designers, directors, producers, safety experts and developers on a mission to save lives.
We are looking for an experienced mobile developer that can drive the development of both Android and iOS native application for our platform. Ideally this means, you have applications published in both stores.
Drop me a note to jack.u@irmi.com