Featured Articles

Intel releases tiny 3G cell modem

Intel releases tiny 3G cell modem

Intel has released a 3G cellular modem with an integrated power amplifier that fits into a 300 mm2 footprint, claiming it…

More...
Braswell 14nm Atom slips to Q2 15

Braswell 14nm Atom slips to Q2 15

It's not all rosy in the house of Intel. It seems that upcoming Atom out-of-order cores might be giving this semiconductor…

More...
TSMC 16nm wafers coming in Q1 2015

TSMC 16nm wafers coming in Q1 2015

TSMC will start producing 16nm wafers in the first quarter of 2015. Sometime in the second quarter production should ramp up…

More...
Skylake-S LGA is 35W to 95W TDP part

Skylake-S LGA is 35W to 95W TDP part

Skylake-S is the ‘tock’ of the Haswell architecture and despite being delayed from the original plan, this desktop part is scheduled…

More...
Aerocool Dead Silence reviewed

Aerocool Dead Silence reviewed

Aerocool is well known for its gamer cases with aggressive styling. However, the Dead Silence chassis offers consumers a new choice,…

More...
Frontpage Slideshow | Copyright © 2006-2010 orks, a business unit of Nuevvo Webware Ltd.
Tuesday, 15 October 2013 11:37

Java broke Android

Written by Nick Farrell



Not the NSA's fault

Georg Lukas (no not him another one) has penned a detailed post claiming that Google is using what he calls ‘horribly broken’ RC4 and MD5 as the default cipher on all SSL connections of Android devices.

He said that both both are extremely insecure as they are both broken and can be easily compromised, but what is odd is that Android used to use a pretty strong DHE-RSA-AES256-SHA ciphers till Android version 2.2.1. During the release of Android 2.3.4 when RC4 and MD5 were elevated as the default cipher and they are still being used on latest Android versions.

But it seems it was neither NSA spooks nor Google’s intention to weaken Android that was the reason for the dodgy promotion of RC4 and MD5. Lucas found that it was all Oracle’s fault. Google engineers were simply implementing what Java’s Reference Implementation (RI 6) were recommending.

Lucas further said the cipher order on the vast majority of Android devices was defined by Sun in 2002 and taken over into the Android project in 2010 as an attempt to improve compatibility. Question is how soon will it take Google to fix the problem, or will its chums in the NSA say that it can’t.

Nick Farrell

E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
blog comments powered by Disqus

 

Facebook activity

Latest Commented Articles

Recent Comments