Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The principal protections included in SSLSocket that are not provided by the Socket class are [API 20062014]:

  • Integrity Protection: SSL protects against modification of messages by an active wiretapper.
  • Authentication: In most modes, SSL provides peer authentication. Servers are usually authenticated, and clients may be authenticated as requested by servers.
  • Confidentiality (privacy protection): In most modes, SSL encrypts data being sent between client and server. This protects the confidentiality of data so that passive wiretappers won't see sensitive data such as financial information or personal information of many kinds.

...

MITRE CWE

CWE-311, Failure to Encrypt Sensitive Data

Bibliography

[API 2014]

 Class Socket

[Gong 2003]

Section 11.3.3, "Securing RMI Communications"

[Ware 2008]

 

...