@whispersystems Hey, you ARE pinning the flock TLS cert right? Also you should fix the rest of this stuff https://www.ssllabs.com/ssltest/analyze.html?d=flock-sync.whispersystems.org&s=54.244.91.66&latest …
-
-
Replying to @kyhwana
@kyhwana Ugh, for apps@whispersystems controls, why is most of that even ON?! Twisted defaults? Also, WTF 27-year SHA1 certificate?3 replies 0 retweets 0 likes -
Replying to @sindarina
@sindarina The server is its own authority. Makes no difference what the sig hash is or how long the expiration is.@kyhwana2 replies 0 retweets 0 likes -
Replying to @signalapp
@whispersystems@sindarina how does it not matter if someone can generate a self signed cert with the same SHA1? How are you pinning?3 replies 0 retweets 0 likes -
Replying to @kyhwana
@kyhwana Read this, see "Option 1:" http://thoughtcrime.org/blog/authenticity-is-broken-in-ssl-but-your-app-ha/ … There are no CA certs, there's nothing to pin.@sindarina1 reply 0 retweets 0 likes -
Replying to @signalapp
@whispersystems@sindarina see? That's all you had to say right at the start. *link* "we do option A"1 reply 0 retweets 0 likes
@kyhwana @sindarina It's also on the first page of search results for "certificate pinning."
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.