Wayback Machinekoobas.hobune.stream
May JUN Jul
Previous capture 12 Next capture
2021 2022 2023
1 capture
12 Jun 22 - 12 Jun 22
sparklines
Close Help
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
  • Asset Store
  • Get Unity

UNITY ACCOUNT

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account
  • Blog
  • Forums
  • Answers
  • Evangelists
  • User Groups
  • Beta Program
  • Advisory Panel

Navigation

  • Home
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
    • Blog
    • Forums
    • Answers
    • Evangelists
    • User Groups
    • Beta Program
    • Advisory Panel

Unity account

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account

Language

  • Chinese
  • Spanish
  • Japanese
  • Korean
  • Portuguese
  • Ask a question
  • Spaces
    • Default
    • Help Room
    • META
    • Moderators
    • Topics
    • Questions
    • Users
    • Badges
  • Home /
avatar image
0
Question by neshius108 · Jul 17, 2016 at 03:08 PM · wwwsecuritywwwformhttpsssl

WWW/WWWForm, does Unity validate SSL certificates?

I have been reading either contrasting or possibly outdated information regarding this topic.

Does Unity, in July 17th 2016, validate the SSL certificates received when communicating with an HTTPS server?

If so, can someone assure that it is immune to MITM attacks or not? And is this platform dependent or does it work regardless (e.g. Desktop, Web, Android, iOS, etc.)?

Thanks!

Comment
Add comment
10 |3000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

1 Reply

· Add your reply
  • Sort: 
avatar image
1

Answer by QuiZr · Jul 17, 2016 at 06:33 PM

According to unity script reference it does support https protocol so SSL should work on every device (except web, web can only access pages on the same server).

Comment
Add comment · Show 2 · Share
10 |3000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users
avatar image ambientenergy · Oct 18, 2016 at 12:50 AM 1
Share

I've been perfor$$anonymous$$g local testing on PC (windows 10 standalone) with the 'UnityWebRequest' against https://badssl.com/.

Unity appears to not validate any parts of the certificate except for the hostname.

expired, self-signed, untrusted root, and revoked certs don't throw any errors.

This means that someone could create a self-signed certificate for your domain and potentially compromise any user they $$anonymous$$IT$$anonymous$$.

An example attack vector would be overriding the DNS for a large corporate network and pointing it at your server. You could then self-sign a cert for any domain and potentially s$$anonymous$$l passwords or session cookies.

While unity does support the encryption portion of SSL, that doesn't mean the connection is actually secure.

avatar image IgorAherne ambientenergy · Jan 08, 2017 at 12:00 AM 0
Share

@ambientenergy, thanks for this remark

Your answer

Hint: You can notify a user about this post by typing @username

Up to 2 attachments (including images) can be used with a maximum of 524.3 kB each and 1.0 MB total.

Follow this Question

Answers Answers and Comments

5 People are following this question.

avatar image avatar image avatar image avatar image avatar image

Related Questions

WWW/WWWForm, does Unity validate SSL certificates over HTTPS? 0 Answers

POST a form over HTTPS with unvalidated SSL Certificate 2 Answers

SSL Ciphers? How to set reliable https Rest calls? 0 Answers

WWW and SSL on Android 1 Answer

How to avoid reestablishing an HTTPS request, use Connection: Keep-Alive or reuse WWW object? 2 Answers


Enterprise
Social Q&A

Social
Subscribe on YouTube social-youtube Follow on LinkedIn social-linkedin Follow on Twitter social-twitter Follow on Facebook social-facebook Follow on Instagram social-instagram

Footer

  • Purchase
    • Products
    • Subscription
    • Asset Store
    • Unity Gear
    • Resellers
  • Education
    • Students
    • Educators
    • Certification
    • Learn
    • Center of Excellence
  • Download
    • Unity
    • Beta Program
  • Unity Labs
    • Labs
    • Publications
  • Resources
    • Learn platform
    • Community
    • Documentation
    • Unity QA
    • FAQ
    • Services Status
    • Connect
  • About Unity
    • About Us
    • Blog
    • Events
    • Careers
    • Contact
    • Press
    • Partners
    • Affiliates
    • Security
Copyright © 2020 Unity Technologies
  • Legal
  • Privacy Policy
  • Cookies
  • Do Not Sell My Personal Information
  • Cookies Settings
"Unity", Unity logos, and other Unity trademarks are trademarks or registered trademarks of Unity Technologies or its affiliates in the U.S. and elsewhere (more info here). Other names or brands are trademarks of their respective owners.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • Default
  • Help Room
  • META
  • Moderators
  • Explore
  • Topics
  • Questions
  • Users
  • Badges