Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Other than providing a nice interface what does Charles.app do that something like Burp can't?


There's often more than one piece of software to do something and that's OK. I've hacked up simple MITM proxies myself more than once in the last 15 years.

Charles is not new, it's been around more than 10 years.

I think that generally saying 'what does X do that Y doesn't' comes across as fairly negative, and unless there's some obvious reason why Y should be the default adds little.

I'd never heard of burp, but I had heard of Charles. Is there some obvious reason why burp should be the default?


Never heard of either, but just used both and the free version of Burp seems complete enough and is free. Charles is restricted when free ($50 license) but looks better.

edit: additionally, Burp uses a custom certificate instead of a default one for all Charles users


Nothing really - I suspect that Charles is more approachable for the average person though. And besides, I hadn't spotted any alternatives when I wrote the article ;)


That's fair enough, I didn't mean the comment to sound negative (which is how it has been taken, looking at the number of down votes).

Nice article by the way, when attempting to extract data from a site looking at their mobile app is the best thing to do :)


Proxy.app from Websecurify is native Mac proxy and it is pretty good too.


Or excellent mitmproxy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: