How SSL Kill Switch works on iOS 12
nabla-c0d3.github.io
nabla-c0d3.github.io
Information: https://github.com/kendfinger/AppleCache#methodology
Tools: https://github.com/kendfinger/AppleCache/tree/master/tools
I wonder what is the space cost of statically adding trimmed down SSL library. Apps are easily 100+ MB these days.
I believe Uber talked publicly about adopting cronet, and Facebook gave a talk about mobile proxygen (though it is not open-source). If you pop open the Netflix and Youtube apps, you will likely see the same.
https://github.com/nabla-c0d3/ssl-kill-switch2/pull/72/files
https://codeshare.frida.re/@machoreverser/ios12-ssl-bypass/
Here's another Frida snippet that'll extract the TLS keys so traffic can be decrypted (magic number in the code might need changing for iOS 13 though)
What would you have chosen? And why?
Maybe they want to prevent another possible goto fail[2] bug?
A few reasons why can be found here: https://blog.cloudflare.com/make-ssl-boring-again/.
Summary I recall from looking into LibreSSL website some time ago: OpenSSL has a lot of cruft and does weird things like implements its own memory allocator. Most of this is because it supports an extremely wide variety of platforms (I think things like VAX and Amiga). This makes tools that try to detect things like buffer overflows not work properly, which is what Heartbleed was.
There have been many minor versions of OpenSSL released to update security vulnerabilities since Heartbleed.