Security Blog
The latest news and insights from Google on security and safety on the Internet
Introducing nogotofail—a network traffic security testing tool
4. studenoga 2014.
Google is committed to increasing the use of TLS/SSL in all applications and services. But “
HTTPS everywhere
” is not enough; it also needs to be used correctly. Most platforms and devices have secure defaults, but some applications and libraries override the defaults for the worse, and in some instances we’ve seen platforms make mistakes as well. As applications get more complex, connect to more services, and use more third party libraries, it becomes easier to introduce these types of mistakes.
The Android Security Team has built a tool, called
nogotofail
, that provides an easy way to confirm that the devices or applications you are using are safe against known TLS/SSL vulnerabilities and misconfigurations. Nogotofail works for Android, iOS, Linux, Windows, Chrome OS, OSX, in fact any device you use to connect to the Internet. There’s an easy-to-use client to configure the settings and get notifications on Android and Linux, as well as the attack engine itself which can be deployed as a router, VPN server, or proxy.
We’ve been using this tool ourselves for some time and have worked with many developers to improve the security of their apps. But we want the use of TLS/SSL to advance as quickly as possible. Today, we’re releasing it as an
open source project
, so anyone can test their applications, contribute new features, provide support for more platforms, and help improve the security of the Internet.
Posted by Chad Brubaker, Android Security Engineer
1 komentar :
Pattie
kaže...
Good information
4. studenoga 2014. u 13:51
Objavi komentar
Oznake
#sharethemicincyber
#supplychain #security #opensource
AI Security
android
android security
android tr
app security
big data
biometrics
blackhat
C++
chrome
chrome enterprise
chrome security
connected devices
CTF
diversity
encryption
federated learning
fuzzing
Gboard
google play
google play protect
hacking
interoperability
iot security
kubernetes
linux kernel
memory safety
Open Source
pha family highlights
pixel
privacy
private compute core
Rowhammer
rust
Security
security rewards program
sigstore
spyware
supply chain
targeted spyware
tensor
Titan M2
VDP
vulnerabilities
workshop
Archive
2026
tra
ožu
velj
sij
2025
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2024
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2023
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2022
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2021
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2020
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2019
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2018
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2017
pro
stu
lis
ruj
srp
lip
svi
tra
ožu
velj
sij
2016
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2015
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
sij
2014
pro
stu
lis
ruj
kol
srp
lip
tra
ožu
velj
sij
2013
pro
stu
lis
kol
lip
svi
tra
ožu
velj
sij
2012
pro
ruj
kol
lip
svi
tra
ožu
velj
sij
2011
pro
stu
lis
ruj
kol
srp
lip
svi
tra
ožu
velj
2010
stu
lis
ruj
kol
srp
svi
tra
ožu
2009
stu
lis
kol
srp
lip
ožu
2008
pro
stu
lis
kol
srp
svi
velj
2007
stu
lis
ruj
srp
lip
svi
Feed
Follow @google
Follow
Give us feedback in our
Product Forums
.
1 komentar :
Good information
Objavi komentar