Sat.Apr 23, 2011 - Fri.Apr 29, 2011

article thumbnail

Fiddling with Chromium's new certificate pinning

Scary Beasts Security

Over the past few years, there have been various high-profile incidents and concerns with the Certificate Authority-based infrastructure that underpins https connections. Various different efforts are underway to tackle the problem; many are enumerated here: [link] And in terms of things baked directly into the browser, we have things like Firefox's Certificate Patrol add-on: [link] My colleague Adam Langley summarized some features and directions we've been exploring in Chromium recently, it's