Is K-9 Mail susceptible to MITM attacks?
0
votes
1
answer
165
views
I am using K-9 Mail on Android and have set the SSL option to 'SSL (strict)'.
My understanding is that with this option K-9 definitely requires a valid SSL certificate which is issued by a trusted CA, i.e. no self-signed certificates.
What I am wondering about is whether K-9 actually evaluates the CN field in the certificate, i.e. whether it only accepts a certificate as valid and trusted if the CN and the mail server's DNS name match. This is IMO a fundamental requirement in order to not fall for MITM attacks. If K-9 did not match those, in the worst case K-9 would accept any (wildcard) certificate presented on the condition that is has been signed by a trusted CA.
Has anyone tested/confirmed/verified that this is not the case?
Asked by user3425645
(1 rep)
Mar 16, 2014, 12:46 PM
Last activity: Oct 18, 2016, 03:59 PM
Last activity: Oct 18, 2016, 03:59 PM