4 ms·
Could you go about describing how this would work for a 3rd party app like Uber for example?
by nstj 9y ago
Could you go about describing how this would work for a 3rd party app like Uber for example?
- gregsadetsky 9y agoThere was a discussion some time ago about mitmproxy (a tool similar to Charles) and specifically about certificate pinning / iOS apps. See here[0] It seems like you need a jailbroken device, and that there are tools such as SSL Kill Switch[1] [0] https://news.ycombinator.com/item?id=15757878 https://news.ycombinator.com/item?id=15757878 [1] https://github.com/iSECPartners/ios-ssl-kill-switch https://github.com/iSECPartners/ios-ssl-kill-switch
- saagarjha 9y agoI've never done this personally, but I'm pretty sure there is no way to protect against hooking and/or patching functions in Secure Transport (iOS's low-level TLS stack), since all network traffic goes through these APIs. I'm sure there's something similar in Android.
- nstj 9y agoSure, but then you'd have to JB the phone. Most of this stuff is pretty straightforward, but not exactly 'trivial' - especially given the context is an iOS app specifically aimed at making MITM easier.
- saagarjha 9y agoCertificate pinning is inherently security by obscurity; it's intended as an annoyance for anyone trying to reverse-engineer the service, rather than an insurmountable barrier.
- dannyw 9y agoCertificate pinning is also a secure way of protecting against MITM attacks, mis-issued certs, and enterprise proxies.
- saagarjha 9y agoYes: that's what it should be used for. It's not a way to keep your HTTP REST API private.
- kiliankoe 9y agoBasically anything you do client-side falls into that category. If your code runs on my device, there's not much you can do to stop me from fiddling with it.
- tinus_hn 9y agoIt’s intended against a rogue CA supplying certificates for a service they shouldn’t be supplying certificates for. For instance if a CA gives a CA certificate to a government running an SSL inspection service.
- ce4 9y agoYou're not forced to use system facilities for TLS on Android. Back when you needed up to date TLS support for your app on older Android versions you would use e.g. BouncyCastle instead of the system's TLS facilities. Probably the same for iOS.
- sjtgraham 9y agoYou can still patch statically linked libraries. Either statically in an editor and resign or dynamically by changing page protection to rwx, and writing a jump to the alternative implementation. Latter requires entitlements, or jailbreak on iOS.
- saagarjha 9y agoSo just figure out which library they’re using and patch that.
- ce4 9y agoThat's right, there are many ways. I just wanted to point out that you could roll your own tls.