To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections

نویسندگان

  • Marten Oltrogge
  • Yasemin Acar
  • Sergej Dechand
  • Matthew Smith
  • Sascha Fahl
چکیده

For increased security during TLS certificate validation, a common recommendation is to use a variation of pinning. Especially non-browser software developers are encouraged to limit the number of trusted certificates to a minimum, since the default CA-based approach is known to be vulnerable to serious security threats. The decision for or against pinning is always a tradeoff between increasing security and keeping maintenance efforts at an acceptable level. In this paper, we present an extensive study on the applicability of pinning for non-browser software by analyzing 639,283 Android apps. Conservatively, we propose pinning as an appropriate strategy for 11,547 (1.8%) apps or for 45,247 TLS connections (4.25%) in our sample set. With a more optimistic classification of borderline cases, we propose pinning for consideration for 58,817 (9.1%) apps or for 140,020 (3.8%1) TLS connections. This weakens the assumption that pinning is a widely usable strategy for TLS security in non-browser software. However, in a nominalactual comparison, we find that only 45 apps actually implement pinning. We collected developer feedback from 45 respondents and learned that only a quarter of them grasp the concept of pinning, but still find pinning too complex to use. Based on their feedback, we built an easy-to-use web-application that supports developers in the decision process and guides them through the correct deployment of a pinning-protected TLS implementation.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Why Banker Bob (Still) Can't Get TLS Right: A Security Analysis of TLS in Leading UK Banking Apps

This paper presents a security review of the mobile apps provided by the UK’s leading banks; we focus on the connections the apps make, and the way in which TLS is used. We apply existing TLS testing methods to the apps which only find errors in legacy apps. We then go on to look at extensions of these methods and find five of the apps have serious vulnerabilities. In particular, we find that t...

متن کامل

A client-side analysis of TLS usage in mobile apps

As mobile applications become more pervasive, they provide us with a variety of online services that range from social networking to banking and credit card management. Since many of these services involve communicating and handling of private user information – and also due to increasing security demands from users – the use of TLS connections has become a necessity for today’s mobile applicat...

متن کامل

Crazing Level after Pin Insertion in Anterior Primary Teeth: A Preliminary In Vitro Study

Objectives: This study aimed to investigate dentinal crack rate following parapulpal pin insertion in anterior primary teeth. Methods: Thirteen sound freshly extracted primary canine teeth were horizontally sectioned 1 mm above the cementoenamel junction (CEJ). All samples were thoroughly inspected to ensure that the teeth had no cracks. The teeth were then mounted in acrylic blocks...

متن کامل

بررسی تاثیر استفاده از محافظ گچی در شل‌شدگی و عفونت محل پین پروگزیمال تیبیا

Background: Pin loosening and infection in skeletal traction are important problems in orthopedic surgery and methods which are usually used to manage these problems, are costly and sometimes complicated. In this study, the efficacy of using cast support in infection and loosening of proximal tibial pin was investigated. Methods: In a randomized clinical trial, 60 patients referring to Rasul-e...

متن کامل

Aspiration of a sharp metallic pin in a child: A case report

Introduction: Foreign Body Aspiration (FBA) represents a life-threatening emergency .It occurs primarily in children below 3 years. Generally, the most common aspirated FB is organic material such as nuts or beans. Sharp Foreign Bodies (FBs) are of particular concern to the attending clinician, because of their potential to perforate the air passage and cause possible complications. Here in, we...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015