Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Autorschaft

  • Marten Oltrogge
  • Nicolas Huaman
  • Sabrina Amft
  • Yasemin Acar
  • Michael Backes
  • Sascha Fahl

Organisationseinheiten

Externe Organisationen

  • Helmholtz-Zentrum für Informationssicherheit (CISPA)
Forschungs-netzwerk anzeigen

Details

OriginalspracheEnglisch
Titel des SammelwerksProceedings of the 30th USENIX Security Symposium
Seiten4347-4364
Seitenumfang18
ISBN (elektronisch)9781939133243
PublikationsstatusVeröffentlicht - 2021
Veranstaltung30th USENIX Security Symposium, USENIX Security 2021 - Virtual, Online
Dauer: 11 Aug. 202113 Aug. 2021

Publikationsreihe

NameProceedings of the 30th USENIX Security Symposium

Abstract

Android applications have a long history of being vulnerable to man-in-the-middle attacks due to insecure custom TLS certificate validation implementations. To resolve this, Google deployed the Network Security Configuration (NSC), a configuration-based approach to increase custom certificate validation logic security, and implemented safeguards in Google Play to block insecure applications. In this paper, we perform a large-scale in-depth investigation of the effectiveness of these countermeasures: First, we investigate the security of 99,212 NSC settings files in 1,335,322 Google Play apps using static code and manual analysis techniques. We find that 88.87% of the apps using custom NSC settings downgrade security compared to the default settings, and only 0.67% implement certificate pinning. Second, we penetrate Google Play's protection mechanisms by trying to publish apps that are vulnerable to man-in-the-middle attacks. In contrast to official announcements by Google, we found that Play does not effectively block vulnerable apps. Finally, we performed a static code analysis study of 15,000 apps and find that 5,511 recently published apps still contain vulnerable certificate validation code. Overall, we attribute most of the problems we find to insufficient support for developers, missing clarification of security risks in official documentation, and inadequate security checks for vulnerable applications in Google Play.

ASJC Scopus Sachgebiete

Zitieren

Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications. / Oltrogge, Marten; Huaman, Nicolas; Amft, Sabrina et al.
Proceedings of the 30th USENIX Security Symposium. 2021. S. 4347-4364 (Proceedings of the 30th USENIX Security Symposium).

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Oltrogge, M, Huaman, N, Amft, S, Acar, Y, Backes, M & Fahl, S 2021, Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications. in Proceedings of the 30th USENIX Security Symposium. Proceedings of the 30th USENIX Security Symposium, S. 4347-4364, 30th USENIX Security Symposium, USENIX Security 2021, Virtual, Online, 11 Aug. 2021. <https://www.usenix.org/conference/usenixsecurity21/technical-sessions>
Oltrogge, M., Huaman, N., Amft, S., Acar, Y., Backes, M., & Fahl, S. (2021). Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications. In Proceedings of the 30th USENIX Security Symposium (S. 4347-4364). (Proceedings of the 30th USENIX Security Symposium). https://www.usenix.org/conference/usenixsecurity21/technical-sessions
Oltrogge M, Huaman N, Amft S, Acar Y, Backes M, Fahl S. Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications. in Proceedings of the 30th USENIX Security Symposium. 2021. S. 4347-4364. (Proceedings of the 30th USENIX Security Symposium).
Oltrogge, Marten ; Huaman, Nicolas ; Amft, Sabrina et al. / Why Eve and mallory still love Android : Revisiting TLS (in)security in Android applications. Proceedings of the 30th USENIX Security Symposium. 2021. S. 4347-4364 (Proceedings of the 30th USENIX Security Symposium).
Download
@inproceedings{9748a3640d1043ec9bb847963233a65f,
title = "Why Eve and mallory still love Android: Revisiting TLS (in)security in Android applications",
abstract = "Android applications have a long history of being vulnerable to man-in-the-middle attacks due to insecure custom TLS certificate validation implementations. To resolve this, Google deployed the Network Security Configuration (NSC), a configuration-based approach to increase custom certificate validation logic security, and implemented safeguards in Google Play to block insecure applications. In this paper, we perform a large-scale in-depth investigation of the effectiveness of these countermeasures: First, we investigate the security of 99,212 NSC settings files in 1,335,322 Google Play apps using static code and manual analysis techniques. We find that 88.87% of the apps using custom NSC settings downgrade security compared to the default settings, and only 0.67% implement certificate pinning. Second, we penetrate Google Play's protection mechanisms by trying to publish apps that are vulnerable to man-in-the-middle attacks. In contrast to official announcements by Google, we found that Play does not effectively block vulnerable apps. Finally, we performed a static code analysis study of 15,000 apps and find that 5,511 recently published apps still contain vulnerable certificate validation code. Overall, we attribute most of the problems we find to insufficient support for developers, missing clarification of security risks in official documentation, and inadequate security checks for vulnerable applications in Google Play.",
author = "Marten Oltrogge and Nicolas Huaman and Sabrina Amft and Yasemin Acar and Michael Backes and Sascha Fahl",
note = "Funding Information: This research was partially funded by the Deutsche Forschungsgemeinschaft (DFG, German Research Foundation) under Germany{\textquoteright}s Excellence Strategy - EXC 2092 CASA – 390781972). ; 30th USENIX Security Symposium, USENIX Security 2021 ; Conference date: 11-08-2021 Through 13-08-2021",
year = "2021",
language = "English",
series = "Proceedings of the 30th USENIX Security Symposium",
pages = "4347--4364",
booktitle = "Proceedings of the 30th USENIX Security Symposium",

}

Download

TY - GEN

T1 - Why Eve and mallory still love Android

T2 - 30th USENIX Security Symposium, USENIX Security 2021

AU - Oltrogge, Marten

AU - Huaman, Nicolas

AU - Amft, Sabrina

AU - Acar, Yasemin

AU - Backes, Michael

AU - Fahl, Sascha

N1 - Funding Information: This research was partially funded by the Deutsche Forschungsgemeinschaft (DFG, German Research Foundation) under Germany’s Excellence Strategy - EXC 2092 CASA – 390781972).

PY - 2021

Y1 - 2021

N2 - Android applications have a long history of being vulnerable to man-in-the-middle attacks due to insecure custom TLS certificate validation implementations. To resolve this, Google deployed the Network Security Configuration (NSC), a configuration-based approach to increase custom certificate validation logic security, and implemented safeguards in Google Play to block insecure applications. In this paper, we perform a large-scale in-depth investigation of the effectiveness of these countermeasures: First, we investigate the security of 99,212 NSC settings files in 1,335,322 Google Play apps using static code and manual analysis techniques. We find that 88.87% of the apps using custom NSC settings downgrade security compared to the default settings, and only 0.67% implement certificate pinning. Second, we penetrate Google Play's protection mechanisms by trying to publish apps that are vulnerable to man-in-the-middle attacks. In contrast to official announcements by Google, we found that Play does not effectively block vulnerable apps. Finally, we performed a static code analysis study of 15,000 apps and find that 5,511 recently published apps still contain vulnerable certificate validation code. Overall, we attribute most of the problems we find to insufficient support for developers, missing clarification of security risks in official documentation, and inadequate security checks for vulnerable applications in Google Play.

AB - Android applications have a long history of being vulnerable to man-in-the-middle attacks due to insecure custom TLS certificate validation implementations. To resolve this, Google deployed the Network Security Configuration (NSC), a configuration-based approach to increase custom certificate validation logic security, and implemented safeguards in Google Play to block insecure applications. In this paper, we perform a large-scale in-depth investigation of the effectiveness of these countermeasures: First, we investigate the security of 99,212 NSC settings files in 1,335,322 Google Play apps using static code and manual analysis techniques. We find that 88.87% of the apps using custom NSC settings downgrade security compared to the default settings, and only 0.67% implement certificate pinning. Second, we penetrate Google Play's protection mechanisms by trying to publish apps that are vulnerable to man-in-the-middle attacks. In contrast to official announcements by Google, we found that Play does not effectively block vulnerable apps. Finally, we performed a static code analysis study of 15,000 apps and find that 5,511 recently published apps still contain vulnerable certificate validation code. Overall, we attribute most of the problems we find to insufficient support for developers, missing clarification of security risks in official documentation, and inadequate security checks for vulnerable applications in Google Play.

UR - http://www.scopus.com/inward/record.url?scp=85109657506&partnerID=8YFLogxK

M3 - Conference contribution

AN - SCOPUS:85109657506

T3 - Proceedings of the 30th USENIX Security Symposium

SP - 4347

EP - 4364

BT - Proceedings of the 30th USENIX Security Symposium

Y2 - 11 August 2021 through 13 August 2021

ER -