logoalt Hacker News

CTDOCodebasestoday at 10:50 AM2 repliesview on HN

If I remember correctly iPhone apps used to use the devices SSL certificates so you as a user could install your own and man-in-the-middle the traffic to see what was being sent. AFAIK now the apps use certificate pinning.


Replies

floamtoday at 5:38 PM

Certificate pinning is actually rarer today than it was a few years ago. You see it mostly in bank apps, and some system services. It’s not a best practice.

saagarjhatoday at 12:41 PM

Apps can choose to do what they want.