4 ms·
Probably so it'll work through strict proxies.
by sjs 15y ago
Probably so it'll work through strict proxies.
- icebraining 15y agoSince it's HTTPS, those proxies can't see the traffic anyway, so as long as they used SSL on port 443, they could use any protocol on top.
- jodrellblank 15y agoThey potentially can; commercial firewalls can man-in-the-middle HTTPS traffic with a locally signed and organization-computer-trusted SSL certificate.
- icebraining 15y agoYes, you're right, in fact I found a few weeks ago that even Squid can do that.
- skeletonjelly 15y agoFiddler also: http://www.fiddler2.com/fiddler/help/httpsdecryption.asp http://www.fiddler2.com/fiddler/help/httpsdecryption.asp Great for debugging third party https stuff.
- FaceKicker 15y agoHow does that work? I thought all verification of certificates was done in the browser...
- jevinskie 15y agoIT installs the corporate MITM certificate on all of their computers so the browsers accept them as valid.
- latortuga 15y agoWould this still affect the iPhone 4S though? If I understand this all correctly, I think that corporate IT would have to install the self-signed root cert on your phone for Siri to be MITM'd. There's no reason for your phone to trust it otherwise.
- planb 15y agoUnfortunately, Siri does not use the system wide proxy. At least it does not on my iPhone. I tried intercepting the traffic with sshmitm which did work for all other iOS services (e.g. game center) but not for Siri. I'm wondering how these guys sniffed the traffic.
- pflats 15y agoDid you read the article? When the proxy failed, they "ressorted (sic) to using tcpdump on a network gateway". They eventually had to "setup a custom SSL certification authority, add it to our iPhone 4S, and use it to sign our very own certificate"
- planb 15y agoI have read that, but they used tcpdump only to detect what kind of traffic Siri sends after failing to use a normal HTTP proxy. Setting up a custom SSL certification authority is exactly what sshmitm does - but it does not (yet) support transparent proxying. Somehow they have redirected traffic for guzzoni.apple.com to a fake server that acts as a man in the middle (probably simply by using their own DNS), but what I wanted to know is what software they used to fake that server.
- ahlatimer 15y agoThey did mention using their own DNS: "In that case, the simplest solution is to fake an HTTPS server, use a fake DNS server, and see what the incoming requests are."
- trotsky 15y agoNot sure what they used, but this software should be suitable: http://www.thoughtcrime.org/software/sslsniff/ http://www.thoughtcrime.org/software/sslsniff/
- nitrogen 15y agoIt's possible to do transparent proxying using iptables on Linux. Also, as ahlatimer mentioned, pointing the phone at your local DNS server and adding records for all the relevant domains would work, too.