Hey, it's Will. In my last blog post, I mentioned the release of CERT Tapioca, an MITM testing appliance. CERT Tapioca has a range of uses. In this post, I describe one specific use for it: automated discovery of SSL vulnerabilities in Android applications.
more here..........http://www.cert.org/blogs/certcc/post.cfm?EntryID=204
more here..........http://www.cert.org/blogs/certcc/post.cfm?EntryID=204