Q: Your mobile application uses HTTPS to securely communicate with its backend. However, a security researcher installs a custom root CA on their phone, proxies the traffic through a tool like Burp Suite, and successfully intercepts the plaintext API calls. What security control is the mobile app missing?
By default, mobile OS environments and browsers unconditionally trust any certificate signed by a Root CA located in their system trust s...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
By default, mobile OS environments and browsers unconditionally trust any certificate signed by a Root CA located in their system trust store. Because the researcher installed their own malicious Root CA into the phone's trust store, the app blindly accepts the proxy's forged certificates, allowing the MITM attack. To prevent this, the mobile application must implement Certificate Pinning (or Public Key Pinning). The app's source code is hardcoded ("pinned") to only trust the specific cryptographic hash of the backend server's true certificate (or its true CA). When the proxy presents its forged certificate, even if it's considered "valid" by the phone's OS, the application logic will instantly reject the connection because the hash does not match the hardcoded pin.
- Immediate Triage: By default, mobile OS environments and browsers unconditionally trust any certificate signed by
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.