Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why not testing other phones and do a comparison?

Is there any way to decode the content of https? like install certificate on phone and use Man-In-The-Mid to get decoded content, I think it possible. Or the phone may use private protocol(not http/https) and it's hard to decode?

From the report, the tested phone send IMEI and phone number in http, it not mention if the phone send SMS by http or unencrypted form. In my opinion, user don't know if their message send by traditional way or by data connection, the phone need to query if the SMS receiver also enable the company's SMS via data connection feature, if yes, it send via data connection. I think this mechanism is ok for me, but it's better to encrypt the "Query".



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: