Certificate Pinning: Enhancing Client-Side Security
ID: 3f36e740-d260-58a0-b29b-5b41b948d310
STIX ID: report--3f36e740-d260-58a0-b29b-5b41b948d310
Feed Name: HackerOne Blog
Certificate pinning is a client-side TLS defense that binds a host to a known certificate or public key to prevent man-in-the-middle attacks and mitigate risks from compromised certificate authorities. The report explains basic pinning and chain pinning, describes scenarios where pinning is beneficial, provides a Python example for implementing public-key hash checks, and outlines best practices and operational considerations such as fallback mechanisms, pinning intermediate/root certificates, and the trade-off between security and flexibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
