ํ”ผ๋“œ๋กœ ๋Œ์•„๊ฐ€๊ธฐ
๐Ÿ” SSL Pinning in Mobile Apps: Android & iOS (Practical Guide + Trade-offs) - Part 2
Dev.toDev.to
Security

iOS SSL Pinning ๊ตฌํ˜„ ์ „๋žต ๋ฐ ์šด์˜ ๋ฆฌ์Šคํฌ ๋ถ„์„

๐Ÿ” SSL Pinning in Mobile Apps: Android & iOS (Practical Guide + Trade-offs) - Part 2

Armando Picรณn2026๋…„ 5์›” 4์ผ4๋ถ„intermediate

Context

๋„คํŠธ์›Œํฌ ํ†ต์‹  ์‹œ ์„œ๋ฒ„ ์ธ์ฆ์„œ์˜ ์‹ ๋ขฐ์„ฑ์„ ๋ณด์žฅํ•˜์—ฌ MITM ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•˜๋ ค๋Š” ๋ชฉ์ ์˜ ์„ค๊ณ„์ž„. iOS์˜ ์ €์ˆ˜์ค€ ๋„คํŠธ์›Œํ‚น API ํŠน์„ฑ์ƒ ๊ตฌํ˜„ ๋ฐฉ์‹์— ๋”ฐ๋ผ ์•ฑ์˜ ์•ˆ์ •์„ฑ๊ณผ ์œ ์ง€๋ณด์ˆ˜ ๋น„์šฉ์ด ๊ทน๋ช…ํ•˜๊ฒŒ ๊ฐˆ๋ฆฌ๋Š” ํ•œ๊ณ„๊ฐ€ ์กด์žฌํ•จ.

Technical Solution

  • .cer ํŒŒ์ผ ๊ธฐ๋ฐ˜ Certificate Pinning์„ ํ†ตํ•œ ๋Ÿฐํƒ€์ž„ ์ธ์ฆ์„œ ๋ฐ์ดํ„ฐ ์ง์ ‘ ๋น„๊ต ๋ฐฉ์‹ ์„ค๊ณ„
  • ์ธ์ฆ์„œ ๋งŒ๋ฃŒ ์‹œ ์•ฑ ์—…๋ฐ์ดํŠธ๊ฐ€ ๊ฐ•์ œ๋˜๋Š” Fragileํ•œ ๊ตฌ์กฐ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ Public Key Pinning์œผ๋กœ์˜ ์ „ํ™˜
  • Public Key ์ถ”์ถœ ๋ฐ ํ•ด์‹œ ๋น„๊ต๋ฅผ ํ†ตํ•ด ์ธ์ฆ์„œ ๊ฐฑ์‹  ์ฃผ๊ธฐ์™€ ๋ฌด๊ด€ํ•œ ํ†ต์‹  ์•ˆ์ •์„ฑ ํ™•๋ณด
  • ๊ตฌํ˜„ ๋ณต์žก๋„ ๊ฐ์†Œ์™€ ๊ฒ€์ฆ๋œ ๋ณด์•ˆ ๋กœ์ง ์ ์šฉ์„ ์œ„ํ•œ Alamofire ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ServerTrustManager ๋„์ž…
  • SSL Pinning์„ ๋‹จ์ผ ๋ณด์•ˆ์ฑ…์ด ์•„๋‹Œ JWT, API Gateway, WAF์™€ ๊ฒฐํ•ฉํ•œ ๋‹ค์ธต ๋ฐฉ์–ด ์•„ํ‚คํ…์ฒ˜ ๊ตฌ์„ฑ

- ์ธ์ฆ์„œ ์ „์ฒด ๋น„๊ต ๋Œ€์‹  Public Key Pinning์„ ์ฑ„ํƒํ•˜์—ฌ ๊ฐฑ์‹  ์ฃผ๊ธฐ ๋ฆฌ์Šคํฌ ์ตœ์†Œํ™” - ์ธ์ฆ์„œ ๋กœํ…Œ์ด์…˜ ์‹คํŒจ ์‹œ ์„œ๋น„์Šค ์ค‘๋‹จ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•œ Fallback Pin ์„ค์ • ๊ฒ€ํ†  - Charles Proxy ๋“ฑ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ๋„๊ตฌ ์‚ฌ์šฉ ์ œํ•œ์— ๋”ฐ๋ฅธ ๋””๋ฒ„๊น… ํ™˜๊ฒฝ ๋ณ„๋„ ๊ตฌ์ถ• - Fintech ๋˜๋Š” Healthcare ์ˆ˜์ค€์˜ ๊ณ ๋ณด์•ˆ ์š”๊ตฌ์‚ฌํ•ญ ์—ฌ๋ถ€์— ๋”ฐ๋ฅธ ๋„์ž… ๋น„์šฉ ํŽธ์ต ๋ถ„์„

์›๋ฌธ ์ฝ๊ธฐ