Self-Signed, Why Not! Exploiting Insecure Certificate Validation In iOS And macOS

No ratings

Presented at NULLCON GOA 2023 by

TLS is the de facto way of securing network connections. It provides an easy way of ensuring confidentiality, integrity, and authentication for any type of communication. However, like most things in life, this is also too good to be true. TLS allows communicating parties to uniquely authenticate each other by validating each other's certificate. However, iOS and macOS have a history of not validating server certificates insecurely. To make things worse, there have been signs of active attacks against Apple certificate validation. And this is not just history. In this talk, we are going to see some new exploits against both iOS and macOS certificate validation. Just showcasing fixed vulnerabilities is not that interesting, that's why we also learn how these vulnerabilities were found with a newly released tool: certmitm, and how it will catch any new ones that are rolled out. Certmitm automatically discovers insecure certificate validation vulnerabilities in TLS clients by trying to actively exploit any connection passing through it. Let's go on a journey to deep dive into the world of insecure TLS certificate validation in Apple products.