Titanium JIRA Archive
Titanium SDK/CLI (TIMOB)

[TIMOB-23619] Android: Security report reveals many issues about SSL

GitHub Issuen/a
TypeImprovement
PriorityNone
StatusClosed
ResolutionWon't Fix
Resolution Date2016-07-13T11:39:24.000+0000
Affected Version/sn/a
Fix Version/sn/a
ComponentsAndroid
Labelsn/a
ReporterRene Pot
AssigneeAshraf Abu
Created2016-07-11T09:11:03.000+0000
Updated2017-03-23T22:44:48.000+0000

Description

In the attachment there is a security report about Android. There are 8 issues. Many of which are about SSL.

Attachments

FileDateSize
net.roamler (1).pdf2016-07-11T09:10:54.000+00008861

Comments

  1. Ashraf Abu 2016-07-13

    Based on that report, here's the SSL issues: Issue 3: This is used only in development. In Production, this class is not used. Issue 6: It's a feature to can be used to disable/ignore this. Issue 7: Same as Issue 3. Issue 8: We are using it for our bindings. This is already noted in the docs [https://developer.android.com/reference/android/webkit/WebView.html#addJavascriptInterface(java.lang.Object, java.lang.String)] Please note, a number of the issues listed also include Facebook classes. The issues listed has a valid reason to be there and they've actually been noted before to not cause issues. Thanks for the report [~topener].
  2. Ashraf Abu 2016-07-13

    Perhaps issue 8 can have some improvements. Besides that, I'll resolve this issue as Won't Fix.
  3. Lee Morris 2017-03-23

    Closing ticket as Won't Fix with reference to the above comments.

JSON Source