4 ms·
Sure, but then you'd have to JB the phone. Most of this stuff is pretty straightforward, but not exactly 'trivial' - especially given the context is an iOS app
by nstj 9y ago
Sure, but then you'd have to JB the phone. Most of this stuff is pretty straightforward, but not exactly 'trivial' - especially given the context is an iOS app specifically aimed at making MITM easier.
- saagarjha 9y agoCertificate pinning is inherently security by obscurity; it's intended as an annoyance for anyone trying to reverse-engineer the service, rather than an insurmountable barrier.
- dannyw 9y agoCertificate pinning is also a secure way of protecting against MITM attacks, mis-issued certs, and enterprise proxies.
- saagarjha 9y agoYes: that's what it should be used for. It's not a way to keep your HTTP REST API private.
- kiliankoe 9y agoBasically anything you do client-side falls into that category. If your code runs on my device, there's not much you can do to stop me from fiddling with it.
- tinus_hn 9y agoIt’s intended against a rogue CA supplying certificates for a service they shouldn’t be supplying certificates for. For instance if a CA gives a CA certificate to a government running an SSL inspection service.