Bob Stromberg

Running SSL Server test or equivalent for a smartphone app

Discussion created by Bob Stromberg on Nov 11, 2018
Latest reply on Nov 12, 2018 by Keith Shaw

For the ordinary user (in other words, not an app developer), is there a way to run an SSL test on a smartphone app like the SSL server test at SSL Server Test (Powered by Qualys SSL Labs) or the BrowserCheck?

 

Web sites are often telling us to use their app. It's better. Navigation is easier. It's quick and convenient. But is it secure?

 

Related questions:
1. Would such an app need to use the same servers to access a user's account? If so, the SSL Server test would also indicate the security configuration of the server(s) used by the smartphone app.

 

2. Are there other tests a user can make on a smartphone app (equivalent to browser check at Qualys BrowserCheck? I've looked at the OWASP testing guide (OWASP Testing Project - OWASP and the answer is not obvious.

Thanks! Bob Stromberg

Outcomes