The listed problems are not limited to Android apps using SSL. They are also present on non browser apps using SSL for many platforms. See the recent paper from M. GEORGIEV et al. [1]
Furthermore, SSL has been seriously challenged by the community in the last year. This is a good thing as SSL/TLS becomes dominant and thus an interesting target. It is important to discover the vulnerabilities of the protocol and of the different implementations and use. We have made a review of the latest discovered issues of SSL in our security newsletter 22. (http://eric-diehl.com/wp-content/uploads/2012/05/Security-Newsletter-22.pdf)
[1] M. Georgiev, S. Iyengar, S. Jana, R. Anubhai, D. Boneh, and V. Shmatikov, The most dangerous code in the world: validating SSL certificates in non-browser software, Proceedings of the 2012 ACM conference on Computer and communications security, New York, NY, USA: ACM, 2012, pp. 3849.
Discussion on:
Message 3 of 6

































