WRITEUP · MOBILE · TLS · 2026 · @YNSMROZTAS

mTLS on the device

● live clk --:--:-- module · defense

AndroScope already ships an mTLS observer. This note is the surface, not a public break kit.

mtls // liveobserve
radar--:--:--
AndroScope mTLS observer AndroidKeyStore lab only

What mTLS actually adds

Ordinary TLS authenticates the server. Mutual TLS asks the client to present a certificate the server already issued. A proxy that only swaps the server cert still fails the handshake — it has no client key.

TLS client → server cert check → channel one-way trust mTLS client cert + key → server checks both two-way trust APP SERVER APP + CERT SERVER

Enrollment, in one picture

Lab apps that roll their own client identity usually: ask the server for a nonce, generate a key pair on device, sign the nonce, receive a signed client cert, stash the private key next to it. The interesting question is where that private key lives after enrollment.

01 challenge nonce from server 02 prove sign nonce on device 03 issue client cert returns 04 rest key stored — where? AndroidKeyStore / TEE → hardware-bound software KeyPairGenerator + P12 on disk → exportable class

What AndroScope is allowed to say

The defense deck already has an mTLS observer. In an authorized lab build it answers three questions. It does not publish a second APK, a TrustAll manager, or a PEM dump.

E  DEFENSE
50  TLS pinning observer
55  mTLS observer                 ★

session — lab.sample.app
[mTLS] client-cert API present
[mTLS] store class: software KeyStore / PKCS12
[mTLS] AndroidKeyStore: not used for this alias
[mTLS] password for the bag is derived at runtime
         — derived ≠ hardware-bound

mitsec@lab.sample.app:

The actual finding class

A PKCS12 bag encrypted with a long PBKDF2 stretch still decrypts inside the process when the app wants to speak mTLS. If the key was built with a software KeyPairGenerator and never entered AndroidKeyStore, that object is a normal Java key. Runtime instrumentation of an authorized lab build can see the same object the app already unlocked.

That is not “PBKDF2 is weak.” It is “the key is not sealed to hardware.” The public writeup stops there.

AndroScope reports the store class and whether KeyStore was used. It does not ship the extraction recipe or a Burp import path on this site.

Fix

Credit

Enrollment shape and the software-vs-KeyStore distinction are well covered in a public demo by kiratliygt. This page is an AndroScope note, not a reprint, and not a bypass manual.

YUNUS EMRE ÖZTAŞ · MITSEC · LAB BUILD ONLY