Web Hack List

Collected research

Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security

Why eve and mallory love android: an analysis of android SSL (in)security

A static analysis of 13,500 free Google Play apps with the authors' MalloDroid tool found 1,074 containing SSL/TLS code open to man-in-the-middle attack. A manual audit of 100 of them yielded working MITM against 41 apps and a wide range of captured credentials, and a survey of 754 users showed half could not tell whether a session was protected.

Record

Document
Why eve and mallory love android: an analysis of android SSL (in)security
Researcher
Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner and Bernd Freisleben
Published by
teamusec.de
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner and Bernd Freisleben, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .