Reverse engineering and removing Pokémon GO’s certificate pinning
eaton-works.com
eaton-works.com
I didn't have the luxury of Ida Pro back then, but I did find a disassembler. Using that I'd read through the game code until I found the conditional jumps and then patched the original file with 0xE8 (JEZ?), 0xEB (JMP?), or 0xCD 0x90 (NOP?). At one time I used to be able to recognize just the Opcodes in hex, so I might have those wrong today.
When I started working at Egghead, I was granted time by my manger to crack games for our demo station, so we wouldn't have to jump through hoops on the sales floor. For various professional reasons I've had the pleasure of bypassing my company's own protections. Most recently I used Smali/Baksmali to demonstrate how our company's Android beta timebomb was pretty easy to circumvent.
Once a hacker, always a hacker. I have no doubt that this low level tinkering was why I got into computers in the first place and why they still hold my fascination.
________________________
[1] The author of archive.is blocked entire countries in a fit of rageI'm glad Apple is working to keep backdoors out of iOS, but I still prefer Android because I can get into it anyway I want, and do things like the OP without having to resort to backdooring my own device.
I think it's very easy to balance: it's my fortress, because I bought it; I should therefor be allowed and enabled to make it do anything I like. The recent changes which Google have announced — which mean that apps will no longer respect the keys I have installed on my devices — are a move in exactly the wrong direction.
An arbitrarily-complex passphrase of my choosing plus a fingerprint seem reasonable.
And when they do, we should hold them liable for any damage their actions have caused to others, just as we do with all those other tools. Yes, I think liability for allowing one's computer to become part of a botnet is a Good Idea™. Car crashes aren't accidents, and allowing one's computer to become infected isn't accidental either.
Of course if your car crashed because you were driving down a street that a criminal was standing on you'd probably take it back for being terrible.
Not in civilised countries.
> have extensive driving courses
That's what I'm arguing for. In this country the public pays for 12-13 years of education and subsidises another four; I'm arguing that among the subjects we should cover with that massive investment is 'don't be an idiot with computers,' much as we have drivers' ed.
Wow, that sounds bad. Where can I read about this change?
I'll play the devils advocate:
1. From manufacturers perspective, it is very difficult to differentiate if the modification are being intentionally done by the owner of the device, or if the owner is being attacked by a 3rd party (e.g. via malware or JTAG)
2. Ownership ends with the device and the app - you cannot 'own' a service that Google/Niantic/Apple/Steam are providing. They can dictate the terms for providing that service and for an online game like Pokemon, not having access to the service makes the ownership the app and the device pointless.
Also, that remaining 2% has to come from somewhere. People learn to make next-gen tech by playing with and reverse-engineering today's tech.
You'll also notice that the code checks for the certificate length so I'm not sure replacing it with zeroes would have worked.
i haven't personally tried this route yet though
Certificate pinning would prevent you from sniffing the requests, and if they made API changes, you would be unable to analyze them.
So I think the reason Pokevision stopped working is because they may have made API changes, but they've been unable to see what the changes were.
https://www.reddit.com/r/pokemongodev/comments/4vhygk/vps_pr...
"Also, don't use Imgur to host image libraries you link to from elsewhere, content for your website, advertising, avatars, or anything else that turns us into your content delivery network."
https://www.reddit.com/r/IAmA/comments/y81ju/i_created_imgur...
> Nothing has changed in regards to direct linking. I'm not sure what you're seeing exactly, but we'll always allow you to direct link to any image you want.
https://www.reddit.com/r/IAmA/comments/y81ju/i_created_imgur...
> Yes, but you can also look at it as a marketing budget. When people share links, direct or not, the other person now knows about Imgur.
https://www.reddit.com/r/pics/comments/ea4vi/for_the_beginne...
> People linking to the page rather than the image is what keeps imgur going. If everyone linked to the direct image then imgur would have no source of revenue. However, I want people to use the service however they want, and by no means would I ever force anyone to do it one certain way. So, I like it when people link to the page because that's how imgur makes money, but you don't have to do it if you don't want to. I'm just happy that you like the service.
what can that possibly mean? there's no way to use imgur at all without linking to it from elsewhere, except if you visit imgur.com as a destination site (which is fine, but not how imgur has been promoting itself for years)
The rest of the sentence means that <a href="http://imgur.com/foo.jpg" >linking to imgur image</a> is fine but don't directly hotlink <img src="http://imgur.com/foo.jpg "> on your site.
People just want to share a funny picture and that's okay. But if you already own web space somewhere, use it and pay those extra few cents (if anything) to host your own images.
Well, you can shaft users who browse without JavaScript turned on and help destroy the Web, all in one fell swoop!
I particularly hate how imgur requires JavaScript to use. We have had images in HTML for over twenty years now, and for some reason imgur has decided that they are above all that.
But it does sadden me to see the once-promising Web turned into what it has.