Comment Re:Certificate pinning is evil (Score 5, Interesting) 184
So, I wouldn't say that's entirely correct. Certificate pinning is really around not trusting the CA Trust Store certs. i.e., if Verisign is compromised, you wouldn't be affected with a pinned cert. It is a funny thing to pull out though since (and maybe I'm just behind the times), I don't think hardly anyone uses pinned certs these days. There was a push for it 10+ years ago using HPKP but that created more mess than it was worth.
I'm also a bit confused by the GPS thing. Sure, it is compiled in, but wouldn't the user be prompted to allow their location before it could be used? I'm not really even sure that it would prompt to allow without it being declared in the manifest.
Not that I'm defending the app. It just seems more like the adage, "Never ascribe to malice that which can be explained by incompetence".
I'm also a bit confused by the GPS thing. Sure, it is compiled in, but wouldn't the user be prompted to allow their location before it could be used? I'm not really even sure that it would prompt to allow without it being declared in the manifest.
Not that I'm defending the app. It just seems more like the adage, "Never ascribe to malice that which can be explained by incompetence".