4 ms·
The address book is uploaded using TLS/SSL and the author used mitmproxy.
by rryan 15y ago
The address book is uploaded using TLS/SSL and the author used mitmproxy.
- Torn 15y agoD'oh. Would this man-in-the-middle attack have worked if path validated against a CA or stored cert and only submitted the data when it was sure it wasn't being snooped on?
- koenigdavidmj 15y agoNope. Turns out Siri was (at least originally, not sure if it still is) vulnerable to the same attack.
- eurleif 15y agoPresumably Apple could demand the ability to change the certificate an app validated against for testing purposes, if Apple cared enough to do that.
- simon_weber 15y agoI've come across the latter, but it's not a difficult thing to get around if you're willing to play with the binary. You might be able to recognize the stored cert and sub it out with your own, or you can just ensure the branch that validates it never runs.