Comment on Indian Government developed UPI app not allowing me to use the app w/o turning off Adguard.
jaybone@lemmy.zip 1 day ago
“Network with invalid server certificate” lol wtf is that supposed to mean?
Comment on Indian Government developed UPI app not allowing me to use the app w/o turning off Adguard.
jaybone@lemmy.zip 1 day ago
“Network with invalid server certificate” lol wtf is that supposed to mean?
Passerby6497@lemmy.world 1 day ago
It means they know the hash or whatever for their cert, and intentionally fail if there’s any kind of MITM funkiness (which you’d have for an ad blocker doing https intercept)
observantTrapezium@lemmy.ca 1 day ago
It could also be that the app is looking at parameters other than the hash (which would probably be that of the certificate authority rather than the domain’s certificate), like the CN, which is potentially fakeble. You can also try to mess with the APK file, maybe find the strings associated with the certificate check and replace them. I won’t fault the app’s authors for making such a check though, MITM is so easy to do without certificate validation.