iwaxx / blog

iwaxx & Debookee's blog
https://debookee.com
11 stars 1 forks source link

Debookee v6 beta is out - Welcome SSL/TLS decryption #2

Open tomlabaude opened 7 years ago

tomlabaude commented 7 years ago

Update on 4th Sept 17: v6 is not private anymore but in public beta, checkout https://debookee.com and docs

After 7 months of work, I'm pleased to release Debookee 6.0.0 beta, which implements SSL/TLS decryption in less than 4 clic for all your devices.

TL;DR

SSL Module

PRO Module

Credits

This new version is the results of the integration of mitmproxy and SSLsplit. Integrating open source projects in a software is not an easy ethical task. We do our best by contacting them, trying to contribute to their projects and respecting their open source licenses.

Thanks to alpha testers for their patience:

Next steps

Contact / Bug reporting

Current Status

richtestani commented 7 years ago

I finally got a version setup, so far it works well on my own Mac, but my iPhone doesn't seem to work. I installed the cert from mitm, but I the instructions weren't matching my window. Though the cert is listing and everything is trusted, I got an warning about verifying the server identity.

Is this how it will work?

richtestani commented 7 years ago

Also apps like Instagram won't load if targeted.

tomlabaude commented 7 years ago

You may be hitting Key Pinning for some apps, I'm currently writing the docs, but meanwhile, I've added a line in the post above in SSL Module part about it.

For ex, on Mac, Evernote and Slack apps don't accept the fake CA, and there's nothing to do (except patching the apps with fake CA public key hash to validate key pinning)

In Debookee, an enhancement could be to notify the user about Key Pinning for specific URLs. Also the choice for the user to allow the SSL/TLS connection to continue, without being decrypted.

Not sure to understand "The instructions weren't matching my window", we can continue the discussion by email for more details.

To be sure SSL/TLS interception works at its best, on your iPhone, check browsing on a simple website like https://debookee.com, it doesn't use Key Pinning, and you must see HTTP headers.

Else, contact us by email and let's troubleshoot that.

chrismccoy commented 7 years ago

wil i have to re purchase the wm and na license i bought for v5?

tomlabaude commented 7 years ago

No, NA & WM licenses will be valid for all future versions. You paid for some features for lifetime. I've clarified this in the post above, enjoy!

richtestani commented 7 years ago

Hi - I had written to contact on your site, but I got no reply. Where can I write to help get my SSL decryption working.

tomlabaude commented 7 years ago

Richard, I received an email on the 12th of July and replied you on the 14th on your icloud.com email. I've just resent you my answer to both icloud.com and me.com Please update to 6.0.0b2, as there are new warnings concerning HTTP Key Pinning that can't be decrypted. (cf http://docs.debookee.com/en/latest/module_ssl.html#key-pinning)

xenio commented 7 years ago

Thanks, just bought the SSL license and trying the beta.

marca56 commented 6 years ago

@tomlabaude just upgraded to the beta and looks good. I have not had the recurring warnings I mentioned in Slack :)

Good job!

dtigue commented 2 years ago

@tomlabaude I'm trying to find an option to purchase a site license for everyone in the IT department to use @ work. All I see is an option for the personal use combined pro license or the professional use combined pr license. It suggests if we want multiple people to use the software than we should get a site license but no link to where to purchase this.

tomlabaude commented 2 years ago

Hi @dtigue ! Can you contact us by email support@iwaxx.com with number of people in the IT department ? Thanks, Thomas

dtigue commented 2 years ago

As of right now it is only two of us. Moving forward I will be looking to hire one or two more employees to work in in the IT department.

Thanks,

David Tigue @.***

On Aug 12, 2022, at 8:50 AM, tomlabaude @.***> wrote:

Hi @dtigue https://github.com/dtigue ! Can you contact us by email @. @.> with number of people in the IT department ? Thanks, Thomas

— Reply to this email directly, view it on GitHub https://github.com/iwaxx/blog/issues/2#issuecomment-1213132913, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAZFSHUI2M273GT2SVWH4HDVYZJCRANCNFSM4DSKWQ5A. You are receiving this because you were mentioned.

debookee commented 1 year ago

As of right now it is only two of us. Moving forward I will be looking to hire one or two more employees to work in in the IT department. Thanks, David Tigue @. On Aug 12, 2022, at 8:50 AM, tomlabaude @.> wrote: Hi @dtigue https://github.com/dtigue ! Can you contact us by email @. @.> with number of people in the IT department ? Thanks, Thomas — Reply to this email directly, view it on GitHub <#2 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAZFSHUI2M273GT2SVWH4HDVYZJCRANCNFSM4DSKWQ5A. You are receiving this because you were mentioned.

@dtigue Please send us an email support@iwaxx.com, so we could interact privately.