3 ms·
Looks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people
by twleo 3y ago
Looks good.
I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps.
EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.
- jiofj 3y agocert pinning is done by the apps, not by the OS
- ShrimpHawk 3y agoiOS is even easier than Android to add system certificates and can be done without rooting or jailbreaking the device unlike android. cert pinning is done by the apps not the system.
- kelnos 3y agoThat's not necessarily specific to iOS. Certificate pinning is usually done inside an app, not at the OS level. An app can choose to ignore the system certificate store and, for example, pin the cert used to talk to its private API. This is possible both on iOS and Android.
- jeroenhd 3y agoAnother note: cert pinning is made very easy by Android as well (just needs a fingerprint in an XML file). It's a good feature for security (stalkerware remains a huge problem) but it does suck from a reverse engineering standpoint.
- WirelessGigabit 3y agoWould you mind sharing your setup?
- twleo 3y agohttps://github.com/epitron/mitm-adblock https://github.com/epitron/mitm-adblock or https://github.com/barre/privaxy https://github.com/barre/privaxy