From a3ff3914a87cf78428dd0ba7bb7068e54aefcd68 Mon Sep 17 00:00:00 2001 From: Tim Perry Date: Fri, 2 Feb 2024 18:29:23 +0100 Subject: [PATCH] Update incomplete comment in iOS TLS script --- ios/ios-tls-override.js | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/ios/ios-tls-override.js b/ios/ios-tls-override.js index 31baaba..b4c2035 100644 --- a/ios/ios-tls-override.js +++ b/ios/ios-tls-override.js @@ -19,7 +19,8 @@ * Since iOS 11 (2017) Apple has used BoringSSL internally to handle all TLS. This code * hooks low-level BoringSSL calls, to override all custom certificate validation completely. * https://nabla-c0d3.github.io/blog/2019/05/18/ssl-kill-switch-for-ios12/ to the general concept, - * but this + * but note that this script goes further - reimplementing basic TLS cert validation, rather than + * just returning OK blindly for all connections. * * Source available at https://github.com/httptoolkit/frida-interception-and-unpinning/ * SPDX-License-Identifier: AGPL-3.0-or-later