randywestergren.com/reverse-engineering-the-subway-android-app

It’s great to see the increasing adoption of certificate pinning in Android apps. When I run into an app that throws connection errors while attempting to proxy requests, I tend to become more interested in diving deeper. Such was the case when I recently used the Subway app. Reversing the APK revealed cert pinning  among some other interesting findings. Starting the app …


Comments (0)

Sign in to post comments.