4 ms·
Sucks that more and more 3rd party apps are adding pinning to their code so you can't sniff their traffic. This is a great tool for first party debugging thoug
by nstj 9y ago
Sucks that more and more 3rd party apps are adding pinning to their code so you can't sniff their traffic. This is a great tool for first party debugging though :) Nice work Charles!
- reagan83 9y agoCan you describe what this means?
- userbinator 9y agoHardcoding the exact certificate they expect, to prevent MITM attacks. Of course, not every MITM is malicious, as this item shows.
- bigiain 9y agoThen Geotrust, in a petulant hissyfit, email ~20,000 of their customers private keys to DigiTrust - and the carefully laid plans of updating the app with newer ssl certs pinned 12 and 6 months in advance of expiry are - ummmm - revealed to be flawed... Hilarity ensues.
- nstj 9y agoWell, the certs don't _have_ to be shipped with the app, there are workarounds to refresh the certs without sending out a whole new app binary.
- bigiain 9y agoYep - but guess what wasn't done in this case... (Yes, this is a still-trying-to-fix-it real world event... Glad it's not my problem, just one I hear about from people I used to work with...)
- jmiserez 9y agoIf you do pinning, you could just as well use a self signed cert for your API and pin that. If your API is not just used for the app, add a private proxy/load balancer that uses your pinned cert.
- nstj 9y agoCharles works by sitting between a server and a phone. It decrypts traffic from the server, displays this to the user to 'inspect', and then re-encrypts the traffic to be sent to the phone. It re-encrypts the traffic using its own SSL certificate (technically a CA, but no need to get bogged down in details). In many modern apps, code has been added such that an app will only accept traffic which has been encrypted by the original server certificate (ie: the Uber iOS app will only accept traffic which has been encrypted by a certificate from www.uber.com). When Charles attempts to sit between this traffic, the app will not allow network connections, and thus no traffic can be inspected by Charles. This procedure of an app only permitting traffic encrypted by a predefined certificate is known as "certificate pinning" or "pinning" for short. It is becoming more and more common for native apps.
- dannyw 9y agoThe reason for this is primarily to protect against MITM attacks by a hostile network and rogue CA, enterprise proxies, etc.
- saagarjha 9y agoOf course, pinning is trivially defeated if you have debug-level access to the app because you could just intercept any network call.
- nstj 9y agoCould you go about describing how this would work for a 3rd party app like Uber for example?
- gregsadetsky 9y agoThere was a discussion some time ago about mitmproxy (a tool similar to Charles) and specifically about certificate pinning / iOS apps. See here[0] It seems like you need a jailbroken device, and that there are tools such as SSL Kill Switch[1] [0] https://news.ycombinator.com/item?id=15757878 https://news.ycombinator.com/item?id=15757878 [1] https://github.com/iSECPartners/ios-ssl-kill-switch https://github.com/iSECPartners/ios-ssl-kill-switch
- saagarjha 9y agoI've never done this personally, but I'm pretty sure there is no way to protect against hooking and/or patching functions in Secure Transport (iOS's low-level TLS stack), since all network traffic goes through these APIs. I'm sure there's something similar in Android.
- nstj 9y agoSure, but then you'd have to JB the phone. Most of this stuff is pretty straightforward, but not exactly 'trivial' - especially given the context is an iOS app specifically aimed at making MITM easier.
- saagarjha 9y agoCertificate pinning is inherently security by obscurity; it's intended as an annoyance for anyone trying to reverse-engineer the service, rather than an insurmountable barrier.