Nullcon Goa 2023 | Self-Signed, Why Not! Exploiting Insecure Certificate Validation In iOS And macOS
About this talk
In this talk, Aapo Oksman discusses the critical issues surrounding TLS authentication and certificate validation in iOS and macOS. He highlights a history of insecure server certificate validation and presents recent exploits targeting Apple's certificate processes. The session introduces certmitm, a new tool designed to automatically discover insecure certificate validation vulnerabilities in TLS clients. Through demonstrating these exploits and the capabilities of certmitm, the speaker emphasizes the need for improved security measures to protect against these vulnerabilities.
More from this event
See all 25 talks →
Nullcon Goa 2023 | Aftermovie
2:10
Nullcon Goa 2023 | Keynote: Multiplying Threat Intelligence by John Lambert
33:51
Nullcon Goa 2023 | Smashing The State Machine: The True Potential Of Web Race Conditions by James
43:52
Nullcon Goa 2023 | How I Hacked Your Bank Account: A Detailed Look At UPI Security by Nemo
21:08