USENIX Security2020Top-tier venue
Towards HTTPS Everywhere on Android: We Are Not There Yet
Andrea Possemato, Yanick Fratantonio
Abstract
Nowadays, virtually all mobile apps rely on communicating with a network backend. Given the sensitive nature of the data exchanged between apps and their backends, securing these network communications is of growing importance. In recent years, Google has developed a number of security mechanisms for Android apps, ranging from multiple KeyStores to the recent introduction of the new Network Security Policy, an XML-based configuration file that allows apps to define their network security posture. In this paper, we perform the first comprehensive study on these new network defense mechanisms. In particular, we present them in detail, we discuss the attacks they are defending from, and the relevant threat models. We then discuss the first large-scale analysis on this aspect. During June and July 2019, we crawled 125,419 applications and we found how only 16,332 apps adopt this new security feature. We then focus on these apps, and we uncover how developers adopt weak and potentially vulnerable network security configurations. We note that, in November 2019, Google then made the default policy stricter, which would help the adoption. We thus opted to re-crawl the same dataset (from April to June 2020) and we repeated the experiments: while more apps do adopt this new security mechanism, a significant portion of them still do not take fully advantage of it (e.g., by allowing usage of insecure protocols). We then set out to explore the root cause of these weaknesses (i.e., the why). Our analysis showed that app developers often copy-paste vulnerable policies from popular developer websites (e.g., StackOverflow). We also found that several popular ad libraries require apps to weaken their security policy, the key problem lying in the vast complexity of the ad ecosystem. As a last contribution, we propose a new extension of the Network Security Policy, so to allow app developers to embed problematic ad libraries without the need to weaken the security of their entire app.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f7efc96c-3377-42b6-a1dc-b1a3d657251cCited by top-tier papers9
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar et al.USENIX Security 2021 · 45 citations
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- This Sneaky Piggy Went to the Android Ad Market: Misusing Mobile Sensors for Stealthy Data ExfiltrationMichalis Diamantaris, Serafeim Moustakas, Lichao Sun, Sotiris Ioannidis et al.CCS 2021 · 8 citations
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan et al.USENIX Security 2024 · 7 citations
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley et al.NDSS 2026 · 2 citations
Builds on3
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin et al.NDSS 2016 · 114 citations
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 101 citations
Related papers
- Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at ScalePhilipp Beer, Sebastian Roth, Martina Lindorfer, Marco SquarcinaUSENIX Security 2026
- How Safe Is Your Screen? Understanding and Detecting Privacy Leaks in Sensitive ActivitiesYoungseok Kim, Sungho Lee, Sungjae HwangISSTA 2026
- Demystifying Android Non-SDK APls: Measurement and UnderstandingShishuai Yang, Rui Li, Jiongyi Chen, Wenrui Diao et al.ICSE 2022 · 14 citations
- Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile BrowsersMeng Luo, Pierre Laperdrix, Nima Honarmand, Nick NikiforakisNDSS 2019 · 35 citations
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky et al.S&P 2017 · 293 citations
