Your app is using an unsafe implementation of the X509TrustManager

Hi everyone,

I have the following message on my Google Dev. Account for one my apps.

Your app is using an unsafe implementation of the X509TrustManager interface with an Apache HTTP client, resulting in a security vulnerability. Please see this Google Help Center article for details, including the deadline for fixing the vulnerability.

They provided me a link https://developer.android.com/reference/javax/net/ssl/X509TrustManager.html

Does anyone have any idea what this is about?

Thanks in advance.

W.

«13

Comments

  • GamepencilerGamepenciler Artist/Game Developer Member, PRO Posts: 326

    I got this warning at the google developer console. I didn't understood what it meant. Can somebody explain more?
    One thing I'm noticing is that my games are being hacked and being uploaded in another a**H*** website this month so I quess that was the issue.
    Also do I need to wait for a GS update for this?

  • BigDaveBigDave Member Posts: 2,239
    edited February 2016

    panic mode

    But to be honest yeah it scared me. We need that fix urgent I guess all our apps are pulled down for me this would mean ruin.

  • adent42adent42 Key Master, Head Chef, Executive Chef, Member, PRO Posts: 3,224

    Please upgrade your game to 1.24 (and if you are on 1.24, re-generate your app).

  • BigDaveBigDave Member Posts: 2,239

    @adent42
    when did this version come out?

    i updated in january
    with newest build. Right now i have

  • BigDaveBigDave Member Posts: 2,239
    edited February 2016

    because iAd is shut down i have to update all iOS
    because this i have to update all google play

    I read they give us this deadline

    "
    Please address this issue as soon as possible and increment the version number of the upgraded APK. Beginning May 17, 2016, Google Play will block publishing of any new apps or updates containing the unsafe implementation of the interface X509TrustManager.
    "
    https://support.google.com/faqs/answer/6346016

    Can you please tell us a rough estimate when 1.25 comes out because that would be a nice timing.. To have all up to date with the newest version.
    In case there is other stuff that should have an update if required like:
    advertiser SDK'S, chartboost,rev mob etc

    I got a bunch of apps.
    Not beeng salty just this would be interesting if this could be an option to wait that days

  • adent42adent42 Key Master, Head Chef, Executive Chef, Member, PRO Posts: 3,224

    We're looking into another possible source of the issue in another third party library. Give us a bit to get back to you.

  • unbeatenpixelunbeatenpixel Game Developer Member, PRO Posts: 568

    Yes, I published it with 12.24.40 in 23 December and 26 January. Still I have same issue.

    There must be another problem in the build.

  • bloodnitebloodnite Member Posts: 50

    I just noticed this as well in my google play dev console - yay! Thanks for looking into this/hopefully fixing asap!

  • adent42adent42 Key Master, Head Chef, Executive Chef, Member, PRO Posts: 3,224

    If someone could do us a huge favor and republish with 1.24. We found another source for the error that we didn't remove as part of our builds, please give it a shot!

  • GEHMRGEHMR Member, PRO Posts: 6

    I am uploading my Bomber game now

  • GEHMRGEHMR Member, PRO Posts: 6

    As of right now the error has gone away but I will post once the new APK is live on the store

  • Triangularity GamesTriangularity Games Founder/Owner MarylandMember Posts: 140

    Im republishing old games. I will let you know if error goes away.

  • GEHMRGEHMR Member, PRO Posts: 6
    edited February 2016

    Updated in store and no error...I'll check again tomorrow to see if anything changed but it looks good so far

  • Triangularity GamesTriangularity Games Founder/Owner MarylandMember Posts: 140

    @GEHMR thanks for the help. I also republished all of my apps. Some old (8 months) some new (last month), so we can see if a simple republish is the solution for all apps.

  • Triangularity GamesTriangularity Games Founder/Owner MarylandMember Posts: 140

    I regenerated all of my apps and republished them to the google play developer console. It says they published the new version, however the error seems to still be there...I'm going to wait until tomorrow to see if it resolves itself...any info or updates on the problem would be helpful and greatly appreciated.

  • GamepencilerGamepenciler Artist/Game Developer Member, PRO Posts: 326

    This issue came out just yesterday. I was troubled when I noticed it. Problem with my oldier games is I lost my keystore, I may not be able to update them :(

    @BigDave said:
    @adent42
    when did this version come out?

    i updated in january
    with newest build. Right now i have

  • BigDaveBigDave Member Posts: 2,239
    edited February 2016

    @Thorhammer
    damn! Yeah you would only be able to re-publish them with a new keystore.

    @GEHMR
    thanks you for the test and infos
    let us now. Was this an update or a totally new game?

    @Triangularity Games
    So thats what I am a afraid of and you for sure use 1.24 to update your old games?

  • weblantisweblantis Member, PRO Posts: 114

    I updated last week all free apps with the latest version of GS and got the same error this morning with all apps!

  • Triangularity GamesTriangularity Games Founder/Owner MarylandMember Posts: 140

    1.24. (Definately) Also, after republishing all of my games old and new the error seems to still be there but it says it applies to the old apk versions. I'm waiting to see if this changes to the new apks I just published or if it goes away.

  • Triangularity GamesTriangularity Games Founder/Owner MarylandMember Posts: 140

    UPDATE: After republishing all of my games, the error was still there, but for the previous version of the apps. I went to the alerts page and dismissed all instances of the error. With the newly published versions, SO FAR, the error doesn't seem to be there. I will update if the error comes back with the newly republished versions. (I did not change anything within gamesalad; I just re-generated the same exact app and republished it to google play) Hopefully this helps :smiley:

  • unbeatenpixelunbeatenpixel Game Developer Member, PRO Posts: 568

    @Triangularity Games said:
    1.24. (Definately) Also, after republishing all of my games old and new the error seems to still be there but it says it applies to the old apk versions. I'm waiting to see if this changes to the new apks I just published or if it goes away.

    Same. I'm waiting to see too

  • ChunkypixelsChunkypixels Member Posts: 1,114

    Theres multiple threads discussing the issue... just have a quick look through the first page... so your definitely not alone with the issue.

    The GS devs have been looking into it though, and might have sorted it out... but you'll probably find more info in the other threads where its already being discussed :)

  • diogoredindiogoredin Member Posts: 50
    • I was PRO for some time and published my games.

    • I am no longer PRO.

    • I have received a Google Play warning: You are using an unsafe implementation of X509TrustManager

    • I need to update my games until May 17, 2016

    Will GS have a solution for this or are ALL old GS games domed?

    Thanks.

  • wilsongaluchowilsongalucho Member Posts: 180

    Thanks @Chunkypixels I found a bit more info.

  • iKandyiKandy Imagineer of Crazy Shit New York CityMember Posts: 310

    Same problem here. Help us GameSalad.

  • iKandyiKandy Imagineer of Crazy Shit New York CityMember Posts: 310

    Help us GameSalad.

  • jonmulcahyjonmulcahy Member, Sous Chef Posts: 10,408

    luckily GS now allows you to buy Pro on a month to month basis, so you can pay the $29, update all your apps and then cancel.

  • freneticzfreneticz SwedenMember, PRO Posts: 777
    edited February 2016

    ...

  • passmitspassmits Member, PRO Posts: 26

    Is there a newer build for Windows? I see Creator 1.24.42 only for mac.

  • ghermans1ghermans1 Member Posts: 23

    So my membership expired... does this mean I'm SOL unless I subscribe again or can I republish?

Sign In or Register to comment.