Remove overly lax hook on TrustManagerImpl

This isn't required, because our system certificate injection
prepopulates the index used by all trust managers anyway, so they trust
our cert regardless. As configured, the previous hook just trusted _all_
certificates, exposing 3rd party MitM risk - better to keep it strict
for just our certificate where we can.
This commit is contained in:
Tim Perry
2023-10-18 18:29:25 +02:00
parent f9ed941ba5
commit 6279e6e7a6
-13
View File
@@ -66,19 +66,6 @@ const PINNING_FIXES = {
}
],
// --- Native TrustManagerImpl
'com.android.org.conscrypt.TrustManagerImpl': [
{
methodName: 'checkTrustedRecursive',
replacement: () => () => Java.use('java.util.ArrayList').$new()
},
{
methodName: 'verifyChain',
replacement: () => (untrustedChain) => untrustedChain
}
],
// --- Native Conscrypt OpenSSLSocketImpl
'com.android.org.conscrypt.OpenSSLSocketImpl': [