3 ms·
If there were using https it would be keep secret no, with his "Burp" suite of investigation? That look like a sniffing method, not through decompilation - whic
by dehef 9y ago
If there were using https it would be keep secret no, with his "Burp" suite of investigation? That look like a sniffing method, not through decompilation - which is pretty trivial for android source.
Anyway that's strange, or the article isn't technically accurate
- deleted 9y ago[deleted]
- albeebe1 9y agoI've used CharlesProxy to view HTTPS traffic from apps on my phone.
- dehef 9y agoI'm not a pro in security but if you use a valid certificate with a certain domain name (not just a ip), it should be impossible to watch with a proxy in the middle? unless you cheat the certificate which are in the phone maybe?
- albeebe1 9y agohttps://www.charlesproxy.com/documentation/proxying/ssl-proxying/ https://www.charlesproxy.com/documentation/proxying/ssl-prox...
- SallySwanSmith 9y agohttps://www.owasp.org/index.php/Certificate_and_Public_Key_Pinning https://www.owasp.org/index.php/Certificate_and_Public_Key_P... Would be required
- nlo 9y agoEven with HPKP, many libs/apps behave like Firefox/Chrome in this respect: """ Firefox and Chrome disable pin validation for pinned hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored. """ https://developer.mozilla.org/en-US/docs/Web/HTTP/Public_Key_Pinning https://developer.mozilla.org/en-US/docs/Web/HTTP/Public_Key...
- mikestew 9y agoThis might explain it a little better: https://www.charlesproxy.com/documentation/proxying/ssl-proxying/ https://www.charlesproxy.com/documentation/proxying/ssl-prox...