Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Installing a custom SSL root certificate feels like such a good idea. Not.

But I guess in order to get something for free, people are willing to go great lengths in compromizing their security. Remember: By installing that guys SSL root certificate, you basically allow them to MITM not just the App store in-app purchasing (and by extension likely sniff your app store password) but also any other SSL protected site like, say, your webmail provider.



As long as your browser does not pin certificates.


Which safari on iOS doesn't do. Nor does the AppStore app. Obviously. Otherwise, this site wouldn't work


I was referring to the browser sniffing webmail. Is the appstore a browser? I thought it was an application.


Applications outside of browsers use SSL.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: