Last modified: 2013-10-07 23:12:54 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T50436, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 48436 - Implement Certificate Pinning
Implement Certificate Pinning
Status: RESOLVED WONTFIX
Product: Commons App
Classification: Unclassified
General (Other open bugs)
unspecified
All All
: Unprioritized enhancement
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-14 06:34 UTC by Yuvi Panda
Modified: 2013-10-07 23:12 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Yuvi Panda 2013-05-14 06:34:42 UTC
Ensures that our users are safer from Government / Network surveillance
Comment 1 Brion Vibber 2013-05-14 15:10:46 UTC
Do we actually need to pin the cert, or just make sure it's valid?

When we legitimately change certs (expiration, configuration change, etc) we don't want to scare users with a warning...
Comment 2 Yuvi Panda 2013-05-14 15:14:14 UTC
It is already requires to be valid.

We should perhaps start a larger conversation about cert pinning. I will investigate how other browsers and apps do pinning when I'm back online.
Comment 3 Tomasz Finc 2013-10-07 23:12:54 UTC
Let's punt on this for now.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links