Web Hack List

Later archive addition

Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security

A static analysis of 13,500 free Google Play apps with the authors' MalloDroid tool found 1,074 containing SSL/TLS code open to man-in-the-middle attack. A manual audit of 100 of them yielded working MITM against 41 apps and a wide range of captured credentials, and a survey of 754 users showed half could not tell whether a session was protected.

Record

Researcher
Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner and Bernd Freisleben

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith, Lars Baumgärtner and Bernd Freisleben, first published at the original source. Preserved copies are kept so the citation survives its host.