Hacker Newsnew | past | comments | ask | show | jobs | submit | Zephyrix's commentslogin

Distro maintainers aren’t infallible either. At the end of the day it’s up to you to decide where and how much trust you place and do your due diligence from there.

One thing that can be helpful when reasoning about things like this is figuring out what your actual threat model is. What does system compromise look like to you? Data exfiltration, arbitrary code execution, something else?


I’ve tried implementing this a few times on my Apple TV to no avail. I think YouTube has implemented cert pinning on their app now or something. Has anyone else been able to get this working recently?


If your willing to dedicate some time, dig into Frida [0], pinned certs are not a problem.

[0] https://frida.re/docs/home/


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: