← Back to context

Comment by Crazyontap

1 year ago

Why didn't a big company like Snapchat not have certificate pinning? Something is amiss here!?

Snapchat do certificate pinning for it's main API domain. I am not exactly sure why analytics domain are different and why not have certificate pinning. (I thought analytics go through the same API domain, but it must be wrong then).

  • The analytics domain was "sc-analytics.appspot.com" in which the lack of pinning is described at the tail end of the blog post.