From 6279e6e7a661fd6bf01219d62ad7e7646cb8a730 Mon Sep 17 00:00:00 2001 From: Tim Perry Date: Wed, 18 Oct 2023 18:29:25 +0200 Subject: [PATCH] Remove overly lax hook on TrustManagerImpl This isn't required, because our system certificate injection prepopulates the index used by all trust managers anyway, so they trust our cert regardless. As configured, the previous hook just trusted _all_ certificates, exposing 3rd party MitM risk - better to keep it strict for just our certificate where we can. --- android-certificate-unpinning.js | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/android-certificate-unpinning.js b/android-certificate-unpinning.js index dce3153..2d21054 100644 --- a/android-certificate-unpinning.js +++ b/android-certificate-unpinning.js @@ -66,19 +66,6 @@ const PINNING_FIXES = { } ], - // --- Native TrustManagerImpl - - 'com.android.org.conscrypt.TrustManagerImpl': [ - { - methodName: 'checkTrustedRecursive', - replacement: () => () => Java.use('java.util.ArrayList').$new() - }, - { - methodName: 'verifyChain', - replacement: () => (untrustedChain) => untrustedChain - } - ], - // --- Native Conscrypt OpenSSLSocketImpl 'com.android.org.conscrypt.OpenSSLSocketImpl': [