TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Android apps that fail to validate SSL

15 pointsby codewithcheesealmost 10 years ago

5 comments

burnallofitalmost 10 years ago
The spreadsheet links to Vulnerability Note VU#582497 (<a href="http:&#x2F;&#x2F;www.kb.cert.org&#x2F;vuls&#x2F;id&#x2F;582497" rel="nofollow">http:&#x2F;&#x2F;www.kb.cert.org&#x2F;vuls&#x2F;id&#x2F;582497</a>). This links to additional information in CERT Oracle Secure Coding Standard for Java (<a href="https:&#x2F;&#x2F;www.securecoding.cert.org&#x2F;confluence&#x2F;pages&#x2F;viewpage.action?pageId=134807561" rel="nofollow">https:&#x2F;&#x2F;www.securecoding.cert.org&#x2F;confluence&#x2F;pages&#x2F;viewpage....</a>). That states that a compliant solution example may be found in &quot;Android Application Secure Design&#x2F;Secure Coding Guidebook&quot; (<a href="http:&#x2F;&#x2F;www.jssec.org&#x2F;dl&#x2F;android_securecoding.pdf" rel="nofollow">http:&#x2F;&#x2F;www.jssec.org&#x2F;dl&#x2F;android_securecoding.pdf</a>). Which is written in Japanese.
phirealalmost 10 years ago
&quot;Wow, this file is really popular! It might be unavailable until the crowd clears. Try again.&quot;<p>Surely Google&#x27;s infrastructure can manage to serve a spreadsheet!
评论 #10041776 未加载
V-2almost 10 years ago
It&#x27;s down.
评论 #10041319 未加载
评论 #10041230 未加载
alt_almost 10 years ago
Mirror: <a href="https:&#x2F;&#x2F;docs.google.com&#x2F;spreadsheets&#x2F;d&#x2F;1LZx6Bis0L9bZ-B4jDvmamvQmnKpr-GVaDpokLR_b-HM&#x2F;edit?usp=sharing" rel="nofollow">https:&#x2F;&#x2F;docs.google.com&#x2F;spreadsheets&#x2F;d&#x2F;1LZx6Bis0L9bZ-B4jDvma...</a>
stevecaliforniaalmost 10 years ago
So what specifically are they meaning when they say &quot;Fail to validate SSL&quot;? Does that mean they are not certificate pinning?