mercredi 7 janvier 2015

Android phone (Kitkat) list A LOTS of CA under setting->security->Trusted credential,



My Android phone (Kitkat) list a LOTS of CA under setting->security->Trusted credential, does it mean that anyone who has accessed to anyone of those private keys of those CA(s) can monitor or do "Man in the Middle" attack between my phone when it communicate with the internet?


I assume one can monitor not just the browser in the phone, but also all encrypted https communication if any app uses https, correct?


Also, if I installed my own CA into the USER part of the phone, can I monitor all https encrypted communication between my phone and the app's server in the net?


I wouldn't mind knowing more details on what all the apps are talking to the server about me, especially when they are encrypted. :-)





Aucun commentaire:

Enregistrer un commentaire