Comment on Indian Government developed UPI app not allowing me to use the app w/o turning off Adguard.

<- View Parent
observantTrapezium@lemmy.ca ⁨1⁩ ⁨week⁩ ago

It could also be that the app is looking at parameters other than the hash (which would probably be that of the certificate authority rather than the domain’s certificate), like the CN, which is potentially fakeble. You can also try to mess with the APK file, maybe find the strings associated with the certificate check and replace them. I won’t fault the app’s authors for making such a check though, MITM is so easy to do without certificate validation.

source
Sort:hotnewtop