Waboodoo / HTTP-Shortcuts

Android app to create home screen shortcuts that trigger arbitrary HTTP requests
https://http-shortcuts.rmy.ch
MIT License
1.17k stars 113 forks source link

Cryptographic APIs misuses #273

Closed misterAnderson90 closed 2 years ago

misterAnderson90 commented 2 years ago

I'm a PhD student interested in finding security vulnerabilities in open source projects.

We found a total of 37 warnings (indicating potential vulnerabilities) when running the CogniCrypt static analyzer (*) on HTTP Shortcuts for Android (or its library dependencies). We documented each one of these issues in private gists for the sake of confidentiality (non-disclosure).

Can you please let us know whether we can share these gists with you? We are eager to evaluate the perception of developers (e.g. severity of these warnings) and improve HTTP Shortcuts for Android's security, and the quality of the reports of static analysis tools.

(*) https://github.com/CROSSINGTUD/CryptoAnalysis

Waboodoo commented 2 years ago

Hello,

I'd be interested to see that gist, so that I may try and address these warnings.

I expect that some of them are intentional, as the app intentionally allows (i.e., on an opt-in basis) certain things that are not considered good practice (such as sending data in plaintext), as some users have a need for them.

Waboodoo commented 2 years ago

@misterAnderson90

Waboodoo commented 2 years ago

Closing this now as I have not heard back