Certificate pinning
Certificate pinning is the practice of accepting only a specific key or certificate for a host, rather than any certificate that chains to a trusted root.
Certificate pinning is the practice of accepting only a specific key or certificate for a host, rather than any certificate that chains to a trusted root. It narrows trust from the whole certificate authority system to one identity chosen in advance.
#What is actually pinned
Usually a hash of the Subject Public Key Info rather than the certificate itself, so that the host can renew a certificate without breaking the pin as long as the key is retained. Pins may be set on the leaf, on an intermediate, or on both, with a backup pin held for the case where the primary key must be replaced.
Pinning is a supplement to ordinary validation, not a replacement for it. RFC 6125 covers the identity checking that still has to happen underneath.
#Why it matters for scraping
Pinning is what stops you reading a mobile application’s traffic through a proxy. The application refuses the substituted certificate that TLS interception depends on, so the connection fails rather than yielding plaintext. That is the mechanism working as designed. Defeating it requires modifying the application, which raises legal and terms-of-service questions worth answering before the technical ones.
The failure is distinctive: the handshake completes at the appliance and the application then closes the connection itself, usually with no useful error. Seeing traffic reach the middlebox and stop there is the signature, and no amount of proxy configuration changes it.
#The browser story
RFC 7469 defined Public-Key-Pins, an HTTP header letting a site pin itself in visiting browsers. It was withdrawn from major browsers in practice, because an operator who loses the pinned key locks users out of the site for the lifetime of the pin, and because the header offered an attacker a way to do the same deliberately. Pinning survives where the client and the server are shipped by the same party: mobile applications, desktop clients, embedded devices.
#Commonly confused with
IP whitelisting restricts who may connect. Pinning restricts which server identity the client will accept. A proxy does not interfere with a pin unless it terminates TLS, so a pinned application works normally through a plain CONNECT tunnel.