Extracting TLS keys from an unwilling application (2020)
m1el.github.io
m1el.github.io
I'm curious: did you consider hacking the Oculus binary to accept an SSL cert you made yourself, and MITM-ing it to see the traffic?
I'm sure they have it pinned and don't use the OS certs, but you could just overwrite the root cert that must exist in that binary somewhere with your own, right?
Unless they use certificate pinning, which is basically just verifying the CA's are not tampered with. Theoretically that could be attacked as well, but it prevents the "just replace the CA" case.
Is that what he refers to when he says "I didn’t want to add extra root certificates and proxies to inspect all TLS traffic going on the machine", or are we talking about different things?
0: https://hugotunius.se/2020/08/07/stealing-tls-sessions-keys-...
And while not MacOS this eBPF based approach is interesting https://mobile.twitter.com/quarkslab/status/1527726910997815...
Applications with pinned certificates don't use the system certificates at all which fixes the MITM vulnerability I described. You'd need to reverse engineer them in order to change the certificate to one under your control, difficulty can vary depending on how obfuscated the code is.