01 February 2013

Use of SSL in Android Applications

Like the SSL Certificate Validation Issues mentioned before, otherwise benign Android apps can be vulnerable to attacks against SSL/TLS misuse.

Part of the text from the paper Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security by Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner, and Bernd Freisleben

Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner, and Bernd Freisleben's paper Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security have developed a tool to help them assess man-in-the-middle (MITM) attacks. They used this to asses 13,500 popular free apps and discovered that over a thousand of them were susceptible to this type of attack.

Misuse cases covering trusting all certificates, allowing all hostnames, trusting many Certificate Authorities (CA) and mixed-mode/no SSL are discussed. The paper has many useful references, and pointers to some tools that can be used to assess the use of SSL/TLS in Android applications.

Posted on: 01 February 2013 at 10:28 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Use of SSL in Android Applications
http://www.clerkendweller.com/2013/2/1/Use-of-SSL-in-Android-Applications
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2013/2/1/Use-of-SSL-in-Android-Applications
Requested by 184.73.7.143 on Thursday, 20 June 2013 at 00:20 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2013 clerkendweller.com