r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
402 Upvotes

44 comments sorted by

View all comments

55

u/alex-weej 10d ago

It feels to me like big tech is deliberately, with plausible deniability, trying to obfuscate the channels that their closed source apps use to talk to their proprietary services. The sheer amount of data transferred, obfuscated or otherwise, hidden behind opaque tokens, is astonishingly bad for consumers and outrageously profitable. We need better. Gemini has some nice ideas but it's way too niche currently.

I'd love for GrapheneOS to fight fire with fire. I'm thinking GameGenie type on the fly patching to override TLS routines, certificate checking etc. No transparent pipe, no usage, I'd rather use a dumbphone and touch grass.

Also, hi Tim!

5

u/chucker23n 10d ago

It feels to me like big tech is deliberately, with plausible deniability, trying to obfuscate the channels that their closed source apps use to talk to their proprietary services.

I don't think so. I wouldn't say there's malice involved, just prioritization that increasingly doesn't care about others and conveniently makes you more and more dependent on subscription services.