4 ms·
Armchairing here, but from a quick gloss over the article it seems like it should be quite easy to stub out: > this new approach reads certificates from /apex/
by DistractionRect 3y ago
Armchairing here, but from a quick gloss over the article it seems like it should be quite easy to stub out:
> this new approach reads certificates from /apex/com.android.conscrypt/cacerts, when it exists.
Much like the how the current work arounds for safetynet, hiding root, and hiding magisk work, it should be possible to hide /apex/com.android.conscrypt/cacerts from select processes as needed to make it fail over to the old way.