Skip to content

Comment on Bypassing OpenSSL Certificate Pinning in iOS Appsparent

Comments

Note that the associated whitepaper discusses using Cydia -- specifically cycript -- to do the same thing.

Yes, often times that can be sufficient. If you just want to study the protocol or build a custom client. Often times one would like to modify messages of the protocol in order to find flaws in either the server or the client and the ability to man-in-the-middle the protocol makes that easier, in my opinion.

For completeness, the whitepaper is here: http://matasano.com/research/bypassing_openssl_pinning.pdf

Awesome article and white paper.

(Modifying the binary is much more fun to blog about, though.)

jerematasno thanks for mentioning cycript. I didn't know about it. Just watched Saurik's intro video. Very fascinating.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.