From 1eb350a980fef40baaa341c84f9eacc618fc8755 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andri=20=C3=93skarsson?= Date: Mon, 2 Mar 2026 17:24:54 +0100 Subject: [PATCH] Update cert-pinning docs to mention automatic detection The circuit breaker now handles cert-pinned hosts automatically. Updated README and landing page to reflect this, while keeping the manual @@||domain^ rule as a documented fallback. --- README.md | 2 +- web/index.html | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index a9d008d..45b0824 100644 --- a/README.md +++ b/README.md @@ -163,7 +163,7 @@ Solutions like [Pi-hole](https://pi-hole.net/) and [AdGuard Home](https://github ### Disadvantages - **CA certificate required**: Every device must trust the proxy's CA certificate. This adds setup friction and has security implications — the proxy can decrypt all HTTPS traffic. -- **Certificate-pinned apps may break**: Some apps (banking, security) use certificate pinning and will reject the proxy's MITM certificates. These need passthrough rules (`@@||domain^`). +- **Certificate-pinned apps**: Some apps (banking, security) use certificate pinning and will reject the proxy's MITM certificates. The proxy detects repeated handshake failures and automatically switches these hosts to passthrough. You can also manually add passthrough rules (`@@||domain^`). - **Higher resource usage**: Decrypting, inspecting, and re-encrypting every HTTPS connection is more resource-intensive than responding to DNS queries. - **More complex setup**: Requires proxy configuration (PAC files or transparent mode with firewall rules) on top of CA certificate installation, compared to just changing a DNS server address. - **HTTP-only**: Does not block non-HTTP traffic. DNS blockers intercept all protocols (QUIC, raw TCP, etc.) at the domain level. diff --git a/web/index.html b/web/index.html index 3d4113f..e337bca 100644 --- a/web/index.html +++ b/web/index.html @@ -1263,7 +1263,7 @@ td:first-child {
🏦

Cert-pinned apps need exceptions

-

Banking apps, security tools, and some system services use certificate pinning and will reject MITM certs. Add passthrough rules (@@||domain^) for these.

+

Banking apps, security tools, and some system services use certificate pinning and will reject MITM certs. The proxy detects this automatically and switches to passthrough. You can also add manual rules (@@||domain^).

📱
-- 2.51.2