# Certificate pinning is great in stone soup

DevFeed: [Certificate pinning is great in stone soup](<https://devfeed.tech/articles/certificate-pinning-is-great-in-stone-soup-36723.md>)

Original publisher: [Read original article](<https://shostack.org/blog/certificate-pinning-is-great-in-stone-soup/>)

Author: Adam

Published: 2017-05-23T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [bootloader](<https://devfeed.tech/tags/bootloader.md>), [devices](<https://devfeed.tech/tags/devices.md>), [iot](<https://devfeed.tech/tags/iot.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article argues that certificate pinning cannot protect an IoT device from an owner who can modify its files or binaries. Effective protection against certificate replacement requires a trusted platform that loads only signed binaries, and the appropriate mitigation depends on the device's threat model, requirements, and cost constraints.

## Source excerpt

[no description provided]