4 ms·
Does this only occur when the user logs into iCloud using the web, or does it happen on the device as well? Does anyone know if iOS uses certificate pinning wh
by hiraki9 12y ago
Does this only occur when the user logs into iCloud using the web, or does it happen on the device as well?
Does anyone know if iOS uses certificate pinning when connecting to iCloud services, and if so if that is sufficient to prevent against this type of attack?
- preek 12y agoIt's a classic MITM which includes switching of the SSL certificate. In regular browsers the user would need either to confirm that they know what they are doing (Firefox) or not get to the page at all (Chrome). I'm not an iOS dev, but I do not think that the iOS SDK would allow for invalid certificates. Then Apple could just go ahead and not use any encryption at all. The 'hack' in the article works, because users ignore security warnings or even use a browser that is clearly made to easily snoop on people.