Dec. 2, 2023, 10:10 p.m. | Security BSides San Francisco

Security BSides San Francisco www.youtube.com

Stick a Pin in Certificate Pinning: How to Inspect Mobile Traffic and Stop Data Exfiltration
Gopal Jayaraman

With the rise of encrypted traffic, more and more companies are deploying SSL inspection platforms to decrypt SSL. Unfortunately, these companies quickly discover that they cannot decrypt all traffic, particularly communications to mobile apps that use certificate pinning.

What is certificate pinning? It’s a method of preventing Man in the Middle (MitM) attacks by validating server certificates against known, approved certificates or hashes …

bsidessf cert certificate certificate pinning companies data data exfiltration decrypt discover encrypted encrypted traffic exfiltration inspection mobile mobile traffic pin pinning platforms quickly ssl ssl inspection traffic

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC