3 ms·
Another author here. With regards to TextSecure specifically, I will quote the code in the paper here: schemeRegistry.register(new Scheme("http", PlainSocketFa
by subiye 14y ago
Another author here.
With regards to TextSecure specifically, I will quote the code in the paper here:
schemeRegistry.register(new Scheme("http", PlainSocketFactory.getSocketFactory(), 80));
schemeRegistry.register(new Scheme("https", SSLSocketFactory.getSocketFactory(), 443));
...
HttpHost target = new HttpHost(hostUrl.getHost(),
hostUrl.getPort(), HttpHost.DEFAULT_SCHEME_NAME);
...
HttpResponse response = client.execute(target, request);
Viewing the code sample from the paper it can be seen that an SSLSocket was meant to be used if the connection was over HTTPS. However this use of the API results in a request being sent over HTTP instead of HTTPS. The argument for CAs not having correct certs makes less sense here in conjunction with the use of SSL API.
We clearly qualify in the paper that this is not exploitable directly.
- tptacek 14y agoNit: "May not result in exploitable vulnerabilities" is not "clear qualification" that a vulnerability isn't exploitable directly.