Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not really a protection though. With a jailbroken phone you could probably change the key with a hex editor or similar. There's also this: https://github.com/iSECPartners/ios-ssl-kill-switch

Also, you're totally screwed if you need to reissue your SSL cert for a security problem (think heartbleed). You'd have to reissue the cert, wait for apple to approve the update, then hope that a significant proportion of your users actually update your app.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: