an unsafe implementation of the interface X509TrustManager from google

前端 未结 3 606
悲&欢浪女
悲&欢浪女 2020-12-05 08:57

I hava an app in Google Play, I received a mail from Google saying that:

Your app(s) listed at the end of this email use an unsafe implementation of t

3条回答
  •  余生分开走
    2020-12-05 09:28

    Your proposed modifications do not fix the security vulnerability. Your code will still accept any correctly formatted certificate, regardless of validity.

    If you aren't sure how to properly verify certificates, you should just remove the custom trust manager. You don't need one unless you are doing something unusual.

提交回复
热议问题