Live data from Hacker News

Cracking Meta's Messenger Certificate Pinning on macOS

texts.blog

81–90 of 136 posts

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#81

[flagged]

They're being hostile to security researchers - app developers don't like people snooping around their private APIs and whatnot. Nor does google, for that matter.

Every move Apple and Google are making on their platforms is about turning the devices we pay for into devices for the companies whose apps we install.

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#83
post #79
post #50

Seems Meta’s (or at least Messenger’s) RE defense is quite lenient here. Should be trivial for them to drop IsUsingSandbox() from prod builds entirely, that’s before we get into advanced obfuscation techniques.

Meta's apps come with entire debug menus in production builds. The string that author found is likely part of such a menu.

Their Android application in particular allows the participation in a developer program which allows access to one of these menus. Not available on macOS and iOS unfortunately!

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#85
post #79

Earlier quoted context omitted.

Meta's apps come with entire debug menus in production builds. The string that author found is likely part of such a menu.

Their Android application in particular allows the participation in a developer program which allows access to one of these menus. Not available on macOS and iOS unfortunately!

Years ago I did manage to get into the impressively huge debug menu in the iOS Messenger app on a jailbroken device. So they do exist there, or at least did back then.

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#87

[flagged]

>I don't get why it has to be this hostile toward developers and why no option is offered to disable it.

If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#88

[flagged]

>I don't get why it has to be this hostile toward developers and why no option is offered to disable it. If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.

I get it, but that's ultimately the user's choice.

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#89

Earlier quoted context omitted.

>I don't get why it has to be this hostile toward developers and why no option is offered to disable it. If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.

I get it, but that's ultimately the user's choice.

That line of thinking leads you to the path where users are free to install malware and give it all the capabilities it needs because the user chose to do so.

Re: Cracking Meta's Messenger Certificate Pinning on macOS

#90

Earlier quoted context omitted.

I get it, but that's ultimately the user's choice.

That line of thinking leads you to the path where users are free to install malware and give it all the capabilities it needs because the user chose to do so.

Yes, if the user want to disable all the protections and choose to install malware it's their choice. You can already do so on *nix, Windows, and macOS (albeit more complicated). Not sure why a phone OS would be different.

Your line of thinking is basically "think of the children".

Post reply on HN