Doing the same on our mobile devices is much more tougher, because we've let feature phones become walled gardens.
Doing the same on our mobile devices is much more tougher, because we've let feature phones become walled gardens.
Not if the app uses certificate pinning, ships its own version of a SSL library and uses code-signing and obfuscation to prevent you messing around with it.
As for the walled garden part: I agree with the general sentiment, but on the other hand I also see the lengths malware authors go to gather data from people. There really is no one-fits-all solution here, because anything that allows the user to intercept and monitor SSL communication can automatically be used by an attacker! :(
Are there desktop apps that behave this way? Atleast in my experience - I haven't come across anything like this on Linux.
And I seriously hope cert pinning gets adopted by more applications.