> We installed mitmproxy on a Mac, configured an iPhone to route traffic through it, and installed the mitmproxy CA certificate on the device. > All HTTPS traffic was decrypted and logged. No modifications were made to the traffic. The app was used as any normal user would use it. Is it really that simple to inspect network traffic on an iPhone, namely to get it to trust the user-installed cert? I do quite a bit of n…
Regardless, it highlights the importance of having control of our own devices, including the ability to easily inspect network traffic. We have the right to know where our data is being sent, and what data is being sent. Meanwhile I've always found it amusing that there's a loud, probably corporate-owned/Big-Tech-brainwashed subset of the "security" crowd who complains about MITM proxies.
We intercepted the White House app's network traffic
61–70 of 85 posts
Re: We intercepted the White House app's network traffic
#6243% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…
Re: We intercepted the White House app's network traffic
#63Government apps should absolutely be held to a higher standard than consumer B2C apps. Loading Google Fonts is one thing — sending telemetry to OneSignal and Facebook from an official government app is a different conversation entirely. In Australia, apps handling government data must comply with the PSPF (Protective Security Policy Framework) and the ISM, which explicitly restrict data flows to untrusted third parti…
> Government apps should absolutely be held to a higher standard than consumer B2C apps Honestly—why? What is in this traffic that mandates heightened scrutiny? It strikes me as simply about brand.
Personally, I want the most stringent CORS settings to read about his gold Sharpie pens.
Re: We intercepted the White House app's network traffic
#6443% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…
Re: We intercepted the White House app's network traffic
#6543% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…
People will excuse anything when it suits them
i am not sure what you are intending to imply. what suits me and how?
i called it boring. flip on a news channel, click any other link on the front page here, or look outside and you will find something more interesting than "app sends a lot of requests to google".
that doesnt mean i think it is good or that i am making an excuse. it means that it is boring. this site is supposed to "optimize for curiosity" or however dang phrases it.
Re: We intercepted the White House app's network traffic
#66> We installed mitmproxy on a Mac, configured an iPhone to route traffic through it, and installed the mitmproxy CA certificate on the device. > All HTTPS traffic was decrypted and logged. No modifications were made to the traffic. The app was used as any normal user would use it. Is it really that simple to inspect network traffic on an iPhone, namely to get it to trust the user-installed cert? I do quite a bit of n…
Yes it was. Imagine, all those (lower) governments holding crisis meetings and sending the video and audio to China. What are the chances that all that stuff was recorded. Nice training data for some deepfakes.
Re: We intercepted the White House app's network traffic
#6743% (of the 158 3rd-party requests) is... google. youtube, fonts, and analytics. 55% if you include facebook and twitter. a government app shouldnt have crazy analytics and tracking and whatever. but i dont think loading google fonts or embedding youtube videos is really all that wild in the grand scheme of things. given the title, i was half expecting some sort of egregious list with, like, palantir and some ICE dom…
Current government tries to steer the ship that is the US in the direction of an autocratic state as can be seen by most of their actions. But it's a huge ship and it takes time, no matter how hard you try (luckily).
Re: We intercepted the White House app's network traffic
#68Earlier quoted context omitted.
"everything else sucks too" is not a great defense for the US govt.
Just because an app embeds YouTube instead of creating their own video hosting solution that does not mean that does not mean that the app sucks.
Re: We intercepted the White House app's network traffic
#69> We installed mitmproxy on a Mac, configured an iPhone to route traffic through it, and installed the mitmproxy CA certificate on the device. > All HTTPS traffic was decrypted and logged. No modifications were made to the traffic. The app was used as any normal user would use it. Is it really that simple to inspect network traffic on an iPhone, namely to get it to trust the user-installed cert? I do quite a bit of n…
iOS still trusts user-installed certs by default, unlike Android's opt-in model.
However, this only applies to apps using the OS TLS stack. Apps packaging their open openssl may use their own set of certificate authorities. Also, most big apps use certificate pinning for most of their domains.
Apps from Twitter or Facebook probably won't work due to pinning. Quick and dirty could-have-been-a-single-web-page apps, such as this one, usually won't bother with any of that, and neither do many tracking libraries.
Of course, malicious apps can detect when someone is using an altered certificate and choose not to send traffic until the MitM is over.
Re: We intercepted the White House app's network traffic
#70Earlier quoted context omitted.
> Government apps should absolutely be held to a higher standard than consumer B2C apps Honestly—why? What is in this traffic that mandates heightened scrutiny? It strikes me as simply about brand.
Despite all the sneed on display, it's currently #4 in the App Store (ahead of Threads, Gmail, and Google Maps) and #1 in News so they did something right. Personally, I want the most stringent CORS settings to read about his gold Sharpie pens.
Not disagreeing. But why should its provenance force a higher standard? It’s a glorified news app, to my understanding. Is its breaching worse for national security than some weather app that had its moment in the sunlight?