<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: certificate pinning - is it a good thing? in CSSLP Study Group</title>
    <link>https://community.isc2.org/t5/CSSLP-Study-Group/certificate-pinning-is-it-a-good-thing/m-p/61146#M154</link>
    <description>&lt;P&gt;First of all, I can virtually guarantee that there would not be a question "Is cert pinning a good thing?".&amp;nbsp; &amp;nbsp;That is way to much like a trivia question for an&amp;nbsp;(ISC)² exam.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;(ISC)² exams are much more about "problem solving" and "applied knowledge".&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, exams are refreshed every 3 years, so what matters with the CSSLP (in theory) is not the state of the art in 2013, but rather what it was on Sep 15, 2020 (and soon, Sep 15, 2023).&amp;nbsp; But, even that rule of thumb fails because when a question stops performing well (e.g. high-scoring exam takers tend to pick the same "wrong" answer), the question is removed from the pool and put on the "fix me" pile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third, the "Official Guide" is but one of about 25 &lt;A href="https://www.isc2.org/Certifications/References" target="_blank"&gt;references&lt;/A&gt; used to build the CSSLP exam. And, the exam is written by certificate holders, not&amp;nbsp;(ISC)² nor textbook authors.&amp;nbsp; So, I would not put much weight in one (old) reference that does not match current practice, regardless of its author.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 02:59:58 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2023-07-25T02:59:58Z</dc:date>
    <item>
      <title>certificate pinning - is it a good thing?</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/certificate-pinning-is-it-a-good-thing/m-p/60837#M148</link>
      <description>&lt;P&gt;This is a topic that comes up more than a few times in exam preparation, either as a control or a possible mitigation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ask because a lot of the CBK is 10 years old and strategies like certificate pinning were common back then.&amp;nbsp; But some of these strategies have been re-examined and found to have flaws.&amp;nbsp; Certificate pinning is one of them.&amp;nbsp; Digicert recommends&amp;nbsp;&lt;A href="https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning" target="_blank" rel="noopener"&gt;to stop certificate pinning&lt;/A&gt;&amp;nbsp; because at times keys have been exposed and outages can occur when certificates expire.&amp;nbsp; Even OWASP tries to steer you towards public key pinning rather than certificate pinning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the purposes of the CSSLP is certificate pinning considered a deprecated control or should I just think back to 10 years ago when a question pops up &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;STRONG&gt; I think the answer to this is yes because I see it in the official curriculum.&lt;/STRONG&gt; But in 2023, no one is recommending this practice anymore.&amp;nbsp; Perhaps the CBK needs to be updated.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 17:13:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/certificate-pinning-is-it-a-good-thing/m-p/60837#M148</guid>
      <dc:creator>terpsfanatic</dc:creator>
      <dc:date>2023-07-14T17:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: certificate pinning - is it a good thing?</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/certificate-pinning-is-it-a-good-thing/m-p/61146#M154</link>
      <description>&lt;P&gt;First of all, I can virtually guarantee that there would not be a question "Is cert pinning a good thing?".&amp;nbsp; &amp;nbsp;That is way to much like a trivia question for an&amp;nbsp;(ISC)² exam.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;(ISC)² exams are much more about "problem solving" and "applied knowledge".&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, exams are refreshed every 3 years, so what matters with the CSSLP (in theory) is not the state of the art in 2013, but rather what it was on Sep 15, 2020 (and soon, Sep 15, 2023).&amp;nbsp; But, even that rule of thumb fails because when a question stops performing well (e.g. high-scoring exam takers tend to pick the same "wrong" answer), the question is removed from the pool and put on the "fix me" pile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third, the "Official Guide" is but one of about 25 &lt;A href="https://www.isc2.org/Certifications/References" target="_blank"&gt;references&lt;/A&gt; used to build the CSSLP exam. And, the exam is written by certificate holders, not&amp;nbsp;(ISC)² nor textbook authors.&amp;nbsp; So, I would not put much weight in one (old) reference that does not match current practice, regardless of its author.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 02:59:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/certificate-pinning-is-it-a-good-thing/m-p/61146#M154</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-07-25T02:59:58Z</dc:date>
    </item>
  </channel>
</rss>

