Author Topic: Insecure cipher selection with AquaMail  (Read 3484 times)

ItsNannerpuss

  • Guest
Insecure cipher selection with AquaMail
« on: June 09, 2014, 10:01:41 am »
I use AquaMail on an Android 4.4.2 device to connect to a private postfix server via SSL.  While reviewing my server's logs I noticed that connections originating from AquaMail are using TLSv1 with cipher RC4-MD5.  RC4 and MD5 are considered quite weak ciphers these days, and I was surprised to see them in use.  This is not a limitation of my server, as I can see traffic coming from other third party servers as well as my other clients using much stronger encryption (DHE-RSA-AES256-SHA, ECDHE-RSA-RC4-SHA, ECDHE-RSA-AES256-GCM-SHA384...).

I haven't found anywhere in AquaMail where these encryption parameters are configurable.  Is it a known limitation that AquaMail doesn't support stronger encryption, or is the app failing to negotiate the ideal ciphers for some reason? 

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Insecure cipher selection with AquaMail
« Reply #1 on: June 09, 2014, 03:20:27 pm »
Development builds (get them on this forum) have a setting for "SSL hardening", in app settings -> networking.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/