Quantcast
Channel: together.jolla.com - Individual question feed
Viewing all articles
Browse latest Browse all 8

Do not automatically accept all SSL certificates

$
0
0
The Mail app is set to automatically accept all SSL certificates by default, which is a security risk. I'm awfully sorry to complain about something *because it works* ( :-) ), but I was unpleasantly surprised when I successfully managed to set up my email account (which uses a self-signed SSL certificate) without the Jolla complaining about the certificate's validity. In all seriousness, though, the device should not blindly trust certificates -- at least not without informing the user. Instead, it should give the user the option to (manually) inspect it and then accept (e.g., by adding an exception, either globally or just for the Mail app) or reject. Alternatively, you could have an option like 'SSL (accept all certificates)' like the default mail app in Android, and make sure that the option 'SSL' rejects all certificates that haven't been signed by a trusted authority.

Viewing all articles
Browse latest Browse all 8

Latest Images

Trending Articles



Latest Images