POSTER: Android + Open Wi-Fis = Broken SSL?
نویسنده
چکیده
In previous work [1] we demonstrated severe problems with the way Android applications use SSL. We performed an in-depth study of 13,500 Android apps and discovered that a large number of apps did not use SSL correctly and thus, were vulnerable to Man-In-The-Middle attacks. To make these threats a reality, an attacker needs to execute an active man-in-the-middle attack (MITMA). While MITMAs are a threat against desktop systems as well, MITMAs against mobile devices are easier to mount, since the use of mobile devices frequently occurs in changing and untrusted environments. In this work, we evaluate the severity of the threat of MITMAs against Android devices which use public Wi-Fis and show how the problems with SSL and the CA infrastructure not only do not protect from MITMAs but can actually facilitate them. While the use of open access points and the evil twin attack [2] are already well known threats against open Wi-Fis, we also show how attackers can even bypass apps that implement secure SSL certificate verification. We conducted an initial Amazon MTurk based study of our attack for Android users which can be used to set up future MITMAs even when SSL is implemented correctly.
منابع مشابه
An Application Package Configuration Approach to Mitigating Android SSL Vulnerabilities
Computing platforms such as smartphones frequently access Web content using many separate applications rather than a single Web browser application. These applications often deal with sensitive user information such as financial data or passwords, and use Secure Sockets Layer (SSL) to protect it from unauthorized eavesdropping. However, recent studies have confirmed a wide-spread misconfigurati...
متن کاملPOSTER: Role Based Access Control For Android (RBACA)
Android as an open platform dominates the booming mobile market. However its permission mechanism is inflexible and often results in over-privileged applications. This in turn creates severe security issues. In this paper, we propose a Role-Based Access Control for Android (RBACA) framework to address this problem. We show how the widely used Role-Based Access Control (RBAC) approach can be app...
متن کاملRemote Monitoring and Control of Industrial Robot based on Android Device and Wi-Fi Communication
Robot control systems are usually complex systems whose users must be well trained to use them. Also, control process is mainly carried out near the robot or by using wired connections. There is a need for a solution that can provide convenient and intuitive robot control with user’s location independence, easy adjustment and simultaneously monitoring of robot motion tasks. Android devices are ...
متن کاملAn Android Powered Wi-Fi Network
Computer networks are used for the easy sharing of data and resources within a closed user group. These networks find use in a plethora of scenarios. This paper describes an App in Android which enables the android devices in a particular Wi-Fi network to join a private wireless network such as an office. Users entitled to use this particular app can share messages and data without using any pa...
متن کاملSMV-Hunter: Large Scale, Automated Detection of SSL/TLS Man-in-the-Middle Vulnerabilities in Android Apps
Many Android apps use SSL/TLS to transmit sensitive information securely. However, developers often provide their own implementation of the standard SSL/TLS certificate validation process. Unfortunately, many such custom implementations have subtle bugs, have built-in exceptions for self-signed certificates, or blindly assert all certificates are valid, leaving many Android apps vulnerable to S...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013