6 ms·
Simply verifying the certificate is not enough, it is simple to decompile and reverse-engineer an IPA to bypass certificate checks. You should NOT be sending s
by loopdoend 13y ago
Simply verifying the certificate is not enough, it is simple to decompile and reverse-engineer an IPA to bypass certificate checks.
You should NOT be sending such sensitive information on other users, encrypted or not. Unless of course you want to continue this trend of violating your user's privacy.
- jokull 13y agoTo clarify, sensitive information is no longer transferred at all. This was hotfixed earlier today.
- e28eta 13y agoGiven access to the device, I find it much easier and simpler to install my own Certificate Authority than to decompile and modify the IPA. The CA can also be provided in a .mobileprofile, installable through email. It also validates as a legitimate certificate, unless the app is looking for a particular certificate, which I think is rare.