22 ms·
> but you could just overwrite the root cert that must exist in that binary somewhere with your own, right? Unless they use certificate pinning, which is basic
by zevv 4y ago
> but you could just overwrite the root cert that must exist in that binary somewhere with your own, right?
Unless they use certificate pinning, which is basically just verifying the CA's are not tampered with. Theoretically that could be attacked as well, but it prevents the "just replace the CA" case.
- _kbh_ 4y agothe attack here is to just invert the compares for all the checks, which means it'll accept any certificate thats not the original, then you can MitM all the traffic with only minor changes to the binary.
- jcalvinowens 4y agoFinding the right branches to flip in the text seems a lot more time consuming than just replacing the cert data, which is probably in one place. Unless it's incredibly obfuscated or something...
- deleted 4y ago[deleted]
- _kbh_ 4y agoIn hindsight this is probably a lot easier.
- jcalvinowens 4y agoIf they don't pin it's trivial. But I strongly suspect they do.