Files
frida-interception-and-unpi…/ios
Tim Perry 140af9b8be Validate the certificate chain (for our CA) when hooking iOS BoringSSL
This is really cool. Rather than just blindly disabling all TLS
validation, we now verify the cert directly against the CA you provide.
We only do extremely basic checks (some more testing required to
validate this provides even basic guarantees) so this shouldn't be
relied for rock-solid TLS validation (probably even after it's been
tested tbh) and it won't handle many real-world cases of CA validation,
but in terms of "do a local MitM while retaining the basics of TLS
protection" it should do a reasonable job, hopefully.
2024-02-02 17:59:16 +01:00
..