Hunting Mobile Tls Pinning And Trust Gaps

Hunt transport trust gaps in a mobile app, where the app accepts a network position it should reject, because it trusts user-added certificate authorities, allows cleartext or mixed connections, disables or misapplies certificate validation, or pins only some connections so an unpinned or fallback path lets a network attacker read or alter traffic the app treats as secure. Use when reviewing how a mobile app establishes and validates its network connections and whether every sensitive connection resists an intercepting network position. Covers user-trusted anchors, cleartext and mixed connections, disabled or permissive validation, and partial or bypassable pinning. The intercepting network position the app fails to reject is the source, the connection the app treats as trusted is the sink, and reading or altering supposedly secure traffic is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-mobile-tls-pinning-and-trust-gaps commit efd2d5028d

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-mobile-tls-pinning-and-trust-gaps