Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: Mobile App TLS connection - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Mobile App TLS connection
Question:

I've been doing some testing on a mobile app to ensure that the connection between the client and the host is encrypted. I've been testing the app on an android device and iOS device. On the iOS device I see the connection occurring with TLSv1.2 and on the android device TLSv1.

I tested the android device using howsmyssl.com and it came back saying that it was fine and using TLSv1.2.

Is this an indication that the app is forcing itself down to TLSv1, and if so is that a problem?

Thanks in advance.
Anonymous

No. It is not a problem. There is no compatibility issues as such. You need TLS to communicate between android and iOS. There is a version difference. It automatically downgrades the version to communicate. If you want to change the version, go to the settings and do it manually. Anonymous

Sign Up for Free or Log In to start participating in the conversation!