HOW TO SECURE YOUR

MOBILE APP

THE EASY WAY
First, the Facts…
163%
increase of mobile
malware in 2012
78%
of the top 100 Android &
iOS apps have been hacked
5%
of popular apps use
tools to defend against hack
attacks
40%
of popular free iOS
apps
AND
80%
of popular free
Android apps
were found to be
hacked
So why should I care…
Cracked mobile apps risk…
Revenue Loss
Unauthorized Access
Intellectual Property Theft
Fraud
Altered User Experience
Brand Damage
Does My App Need
to Be Secure?
YES…but some apps are
at greater risk than others
High Risk Apps
•Ask

Location

•Collect

user info

•Remote

servers
Low Risk Apps
•Alarm
•To

Clocks

Do Lists

•Offline

Apps
If the big guys can’t keep
their mobile app secure,
how can I?
DO…
Use https:// to get content
Maintain updated libraries
Use a secure mobile app (CMS)
Filter inputs at device level
Store in a secure location:
iOS = Built-in Keychain class
Android = Encrypt data
DON’T…
Treat content passed in as trusted
!

Save to “NSUserDefaults" or
“SharedPreferences"
Forget https: ‘GET’ & ‘POST’
Connect to an unsecure backend
!

Use one, static encryption key
!

Skip code reviews with teams
What The Pros Have
to Say About This
“Make sure to encrypt important
files if stored locally. Also,defend
against operating system
vulnerabilities, e.g. for iOS apps,
defend against runtime analysis.”
–- Prateek Gianchandani
Security Researcher
“Don’t keep info that
you aren’t willing to spend
money and time on to protect.
Avoid rolling out your own
authentication, unless security is
your forte of course."
–- Frank Rietta
Web Security Developer
sounds like a lot of work...
anything i can do quickly to
secure my app?
Secure mobile app
optimization tools
Two-Factor
Authentication
Discover Code Flaws
Things to remember
about mobile app
security
The bigger the user base,
the greater the need for
strong security
Mobile users lose their
devices, get them stolen,
and let people borrow them.
!

So protect their data!
If the NSA has taught us
anything…Nothing is hack
proof or 100% secure
OF COURSE THERE’S
A LOT MORE TO LEARN
CHECK OUT THIS ANIMATED
SECURITY GUIDE FOR…

MORE TOOLS, TIPS, & TRICKS
Mobile App Optimization Tools

Mobile App CMS Mobile App Feature Switching
Send content to your app
users in :27 seconds

A circuit breaker for your mobile app
SOURCES:
http://www.mendix.com/think-tank/7-security-compliance-gotchas-in-your-mobile-app-that-you-didnt-think-of-ooops/
http://www.business.ftc.gov/documents/bus83-mobile-app-developers-start-security
http://www.arxan.com/resources/
https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-_Top_Ten_Mobile_Risks
http://highaltitudehacks.com/2013/12/17/ios-application-security-part-25-secure-coding-practices-for-iosdevelopment

How to Secure Your Mobile App the Easy Way