Edit: on 2nd thought even if Facebook can't decrypt a particular app's traffic, just knowing how many requests it makes, how large they are, and how often, could still provide some useful insights into an app's usage.
Edit: on 2nd thought even if Facebook can't decrypt a particular app's traffic, just knowing how many requests it makes, how large they are, and how often, could still provide some useful insights into an app's usage.
> Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. “Data loss prevention” appliances, firewalls, content filters, and malware can use this feature to defeat the protections of key pinning.
http://www.chromium.org/Home/chromium-security/security-faq#...
EDIT: Spaced on the fact this is a phone app. While Chrome on Windows ignores certificate pins, I'm unsure if this also applies to Android / iOS root stores as well.
Source: https://bugs.chromium.org/p/chromium/issues/detail?id=779166
> OK, we're looking at removing dynamic PKP in M69. Static PKP will remain until further notice (we have no active plans to remove it right now).
Jailbreak required, of course.
Many apps do not do pinning currently.