-
@ikoz presenting the details on how to properly do TLS pinning on Android #AndroidSecuritySymposium
-
@ikoz nice takeaway: nr. of trusted root CAs is actually going down over time, iOS trusts (slightly) more than Android, MS ridiculously high
-
@ikoz when pinning goes wrong... That's one example why it is important to do pinning correctly.
-
@ikoz Takeaways: - don't skip chains - don't do X.509 chain validation yourself (!!!) - libraries do it wrong too #AndroidSecuritySymposium