I'm surprised Google itself has not said anything, as they are also at fault for not showing the permissions workflow in the first place.
I'm surprised Google itself has not said anything, as they are also at fault for not showing the permissions workflow in the first place.
> Charles does this by becoming a man-in-the-middle. Instead of your browser seeing the server’s certificate, Charles dynamically generates a certificate for the server and signs it with its own root certificate (the Charles CA Certificate). Charles receives the server’s certificate, while your browser receives Charles’s certificate. Therefore you will see a security warning, indicating that the root authority is not trusted. If you add the Charles CA Certificate to your trusted certificates you will no longer see any warnings – see below for how to do this.
https://www.charlesproxy.com/documentation/proxying/ssl-prox...
It seems you are correct if they use pinning:
> Note that some apps implement SSL certificate pinning which means they specifically validate the root certificate. Because the app is itself verifying the root certificate it will not accept Charles's certificate and will fail the connection. If you have successfully installed the Charles root SSL certificate and can browse SSL websites using SSL Proxying in Safari, but an app fails, then SSL Pinning is probably the issue.
https://www.charlesproxy.com/documentation/faqs/ssl-connecti...
> Charles can be used as a man-in-the-middle HTTPS proxy, enabling you to view in plain text the communication between web browser and SSL web server.
From https://www.charlesproxy.com/documentation/proxying/ssl-prox...
Primarily at fault.
Oauth2 has some serious holes - I have no idea if the Google login page is served by Google, or is simply a copy of their landing page designed to phish for credentials. This needs to be fixed as Oauth is becoming increasingly prevalent. We need some type of web of trust like SSL EV that gives me attestation the Oauth login page is being served by the company that I think it is.
I haven't used to app so I have no idea, just a thought.