Live data from Hacker News

Yes, Android 14 still allows modification of system certificates

g1a55er.net

1–10 of 89 posts

Re: Yes, Android 14 still allows modification of system certificates

#3
Gosh I love linux/root.

I havent needed it on recent androids due to WFH and spending more time on my laptop, but back when I was flying more for work, I was much more into my phone.

Cant remember if it was my motorolla or nexus, but I felt like I had a full fledged laptop in my pocket back then.

Meanwhile, one of the straws that broke the camels back for Windows was the insane difficulty/impossibility of remove bloatware/malware that comes preinstalled with windows 11. In 2023, its mind boggling to think you have easier access to modify a cellphone OS than a desktop OS.

Re: Yes, Android 14 still allows modification of system certificates

#6
post #5

Looks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.

cert pinning is done by the apps, not by the OS

Re: Yes, Android 14 still allows modification of system certificates

#7
post #5

Looks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.

iOS is even easier than Android to add system certificates and can be done without rooting or jailbreaking the device unlike android. cert pinning is done by the apps not the system.

Re: Yes, Android 14 still allows modification of system certificates

#8
post #4

There are ways to bypass any of these restrictions imposed by the Android system, even if they were real. Android ships with eBPF, so you just need root. https://github.com/gojue/ecapture

How many normal phones can you root these days?

Re: Yes, Android 14 still allows modification of system certificates

#9
post #5

Looks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.

That's not necessarily specific to iOS. Certificate pinning is usually done inside an app, not at the OS level. An app can choose to ignore the system certificate store and, for example, pin the cert used to talk to its private API. This is possible both on iOS and Android.

Re: Yes, Android 14 still allows modification of system certificates

#10
post #4

There are ways to bypass any of these restrictions imposed by the Android system, even if they were real. Android ships with eBPF, so you just need root. https://github.com/gojue/ecapture

How many normal phones can you root these days?

Every Pixel phone purchased from the Google store
Post reply on HN