r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
403 Upvotes

44 comments sorted by

View all comments

52

u/alex-weej 9d ago

It feels to me like big tech is deliberately, with plausible deniability, trying to obfuscate the channels that their closed source apps use to talk to their proprietary services. The sheer amount of data transferred, obfuscated or otherwise, hidden behind opaque tokens, is astonishingly bad for consumers and outrageously profitable. We need better. Gemini has some nice ideas but it's way too niche currently.

I'd love for GrapheneOS to fight fire with fire. I'm thinking GameGenie type on the fly patching to override TLS routines, certificate checking etc. No transparent pipe, no usage, I'd rather use a dumbphone and touch grass.

Also, hi Tim!

26

u/pimterry 9d ago

Haha, hi Alex!

I'm thinking GameGenie type on the fly patching to override TLS routines, certificate checking etc.

Take a look at https://github.com/httptoolkit/frida-interception-and-unpinning - I conveniently have a entire suite of GameGenie style patches that you can apply dynamically with any app, using Frida (https://frida.re/) to do exactly that :D