由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
PDA版 - Android 安全: Poor SSL Implementations Leave Many Android Apps Vulnerable
相关主题
nokia 手机怎么收HOTMAIL华为mate9怎么添加yahoo信箱?
一到关键时刻就看出来DotNet架构的网站不行了office2016的Outlook被Gmail认为是less secure APP
大家讨论了半天gmail你们都在什么地方搜索Mobile Apps ?
我觉得应该开题讨论反隐私暴露的技巧Android Gmail 使用公司wifi是否会被监听。
推荐硬件VPN?Sprint Samsung Intercept (Android) Chinese support.
FREAK RSA weak key attackAndroid的发展比我想象的要快
为何gmail收不了office 365 mail?Android销售超过iphone是真的吗
国内的网络真便宜ANDROID MARKET大部分的APPS是要求2.X以上吗?
相关话题的讨论汇总
话题: ssl话题: android话题: apps话题: vulnerable
进入PDA版参与讨论
1 (共1页)
l**n
发帖数: 7272
1
FYI:
https://threatpost.com/en_us/blogs/research-shows-serious-problems-android-
app-ssl-implementations-101912
"There are thousands of apps in the Google Play mobile market that contain
serious mistakes in the way that SSL/TLS is implemented, leaving them
vulnerable to man-in-the-middle attacks that could compromise sensitive user
data such as banking credentials, credit card numbers and other information
. Researchers from a pair of German universities conducted a detailed
analysis of thousands of Android apps and found that better than 15 percent
of those apps had weak or bad SSL implementations. The researchers conducted
a detailed study of 13,500 of the more popular free apps on Google Play,
the official Android app store, looking at the SSL/TLS implementations in
them and trying to determine how complete and effective those
implementations are. What they found is that more than 1,000 of the apps
have serious problems with their SSL implementations that make them
vulnerable to MITM attacks, a common technique used by attackers to
intercept wireless data traffic. In its research, the team was able to
intercept sensitive user data from these apps, including credit card numbers
, bank account information, PayPal credentials and social network
credentials."
a********m
发帖数: 15480
2
os里面都是openssl吧。如果不安全,macosx也一样。app的ssl用别的库不能怪os吧。
1 (共1页)
进入PDA版参与讨论
相关主题
ANDROID MARKET大部分的APPS是要求2.X以上吗?推荐硬件VPN?
哪位给个Android apps 推荐吧FREAK RSA weak key attack
android有啥apps可以给小baby玩为何gmail收不了office 365 mail?
top10 android apps国内的网络真便宜
nokia 手机怎么收HOTMAIL华为mate9怎么添加yahoo信箱?
一到关键时刻就看出来DotNet架构的网站不行了office2016的Outlook被Gmail认为是less secure APP
大家讨论了半天gmail你们都在什么地方搜索Mobile Apps ?
我觉得应该开题讨论反隐私暴露的技巧Android Gmail 使用公司wifi是否会被监听。
相关话题的讨论汇总
话题: ssl话题: android话题: apps话题: vulnerable