- Prompt to allow app to act like VPN
- Having to enter your passcode after said prompt
It's impossible for apps to MITM silently.
I know that without it we wouldn't have amazing apps like https://itunes.apple.com/us/app/adblock/id691121579 , but i'm really not sure if its worth that risk for a common user that apple mostly targets with iOS.
Not sure about the current state though.
Charles desktop app is well respected in the developer community. There is no reason that the iOS app will be treated any differently.
2. You have to trust the Charlesproxy root certificate; again, in the system settings.
You can also click a link to a certificate on a webpage and install it manually on iOS.
How exactly does one go about patching the binary – is there a tutorial somewhere?
Yes
>How exactly does one go about patching the binary – is there a tutorial somewhere?
https://www.guardsquare.com/en/blog/iOS-SSL-certificate-pinn...
There are guides you can google for cracking apps and replacing the certs they compare against. IIRC they all require a jailbroken device.
[1] https://developer.apple.com/library/content/releasenotes/Gen...
[0] Of course you can use the blanket NSAllowsArbitraryLoads to allow plain HTTP everywhere.
Under what conditions does iOS allow an app to do this?
The fact that Android has recently made it impossible to MITM apps is really making me consider switching. I don't think I will, because in many other ways Android is still more open, but the analysis is no longer as lopsidedly in Android's favour.