In Response to The Register “MITM” Article
On Monday, The Register put out an article reporting that CyanogenMod was open to a Man-in-the-middle (MITM) attack via a “0-day” vulnerability relating to a SSL vulnerability in Android’s JSSE from 2 years ago.
There are a number of issues we could point out regarding the nature of this report – the least of which was the lack of contact regarding this topic prior to publishing. Our followup request to the author for direct references to his claims (or a retraction) has gone unanswered, so we are left to refute this article on our own. This is odd as The Register has historically had good messaging with respect to CM, but mistakes happen.
First, JSSE is not used in Android 4.4, which would mean any vulnerability would be applicable to Android 4.3 or below only.
Second, CyanogenMod does not customize this particular level of code – meaning if such a vulnerability …