Session

Trust, But Verify: Certificate Pinning for Flutter

Making Flutter a solid choice for fintech is a challenge. Choice which is not exclusively about reliability, performance and maintenance cost. In high-compliance environments - a penetration test is reckoning. And if your client-server communication isn't hardened, the findings will be uncomfortable to read.

This talk goes beyond ‘use HTTPS’. During this you'll discover the certificate validation hooks Dart exposes and how certificate pinning lets you define exactly who your app trusts, making that trust explicit and verifiable. We will walk through implementation strategies for certificate pinning in Flutter - from the dead-simple to the enterprise-grade.

You'll leave with a decision framework you can defend in your next security review - not just working code, but the reasoning behind it.

Key takeaways:

- Certificate pinning strategies available in Flutter
- SPKI pinning vs full-certificate pinning
- Decoupling security from your app release cycle

Oleksandr Tilnyi

Senior Flutter Engineer @ Deviniti

Wrocław, Poland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top