Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And you still can MITM the traffic, you just have to install your MITM's cert on your device you want to MITM.


This only kind of works. Apps can embed their whole certificate chain and ignore the system one. I don't disagree we should have HTTPS everywhere, but for reverse engineering it does make things harder.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: