Skip to main navigation Skip to search Skip to main content

When TLS Meets Proxy on Mobile

  • University of Iowa
  • Chinese University of Hong Kong

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Increasingly more mobile browsers are developed to use proxies for traffic compression and censorship circumvention. While these browsers can offer such desirable features, their security implications are, however, not well understood, especially when tangled with TLS in the mix. Apart from vendor-specific proprietary designs, there are mainly 2 models of using proxies with browsers: TLS interception and HTTP tunneling. To understand the current practices employed by proxy-based mobile browsers, we analyze 34 Android browser apps that are representative of the ecosystem, and examine how their deployments are affecting communication security. Though the impacts of TLS interception on security was studied before in other contexts, proxy-based mobile browsers were not considered previously. In addition, the tunneling model requires the browser itself to enforce certain desired security policies (e.g., validating certificates and avoiding the use of weak cipher suites), and it is preferable to have such enforcement matching the security level of conventional desktop browsers. Our evaluation shows that many proxy-based mobile browsers downgrade the overall quality of TLS sessions, by for example allowing old versions of TLS (e.g., SSLv3.0 and TLSv1.0) and accepting weak cryptographic algorithms (e.g., 3DES and RC4) as well as unsatisfactory certificates (e.g., revoked or signed by untrusted CAs), thus exposing their users to potential security and privacy threats. We have reported our findings to the vendors of vulnerable proxy-based browsers and are waiting for their response.

Original languageEnglish
Title of host publicationApplied Cryptography and Network Security - 18th International Conference, ACNS 2020, Proceedings
EditorsMauro Conti, Jianying Zhou, Emiliano Casalicchio, Angelo Spognardi
PublisherSpringer Science and Business Media Deutschland GmbH
Pages387-407
Number of pages21
ISBN (Print)9783030578770
DOIs
StatePublished - 2020
Event18th International Conference on Applied Cryptography and Network Security, ACNS 2020 - Rome, Italy
Duration: Oct 19 2020Oct 22 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12147 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Applied Cryptography and Network Security, ACNS 2020
Country/TerritoryItaly
CityRome
Period10/19/2010/22/20

Keywords

  • HTTP tunneling
  • Proxy-based browsers
  • TLS interception

Fingerprint

Dive into the research topics of 'When TLS Meets Proxy on Mobile'. Together they form a unique fingerprint.

Cite this