Episode 427: Sven Schleier and Jeroen Willemsen on Mobile Application Security

Topics covered
Popular Clips
Episode Highlights
Risks
Reverse engineering in mobile apps poses significant security risks, as highlighted by . He emphasizes the ease with which applications can be reverse-engineered, making it crucial for developers to avoid storing sensitive information in easily accessible locations like shared config spaces or plain text files 1. To mitigate these risks, leveraging security standards and integrating them into project management cycles, whether agile or waterfall, is essential 2.
Developers must understand the underlying protocols and not just rely on abstractions, as this knowledge is vital for building effective security tests.
---
Understanding these protocols ensures that developers can implement security measures proactively, rather than leaving it to external entities 3.
Insights
provides insights into the tools and processes involved in reverse engineering. He mentions that while reverse engineering is not typically a developer's skill set, resources like the MSTG project offer detailed write-ups and tools such as Ida, Ghidra, and Frieda to aid in understanding this complex process 4. The availability of source code on platforms like GitHub allows developers to experiment, fix issues, and test their solutions, fostering a hands-on learning environment 5.
The hacking playground was created to demonstrate bad coding practices and provide a training ground for developers and security professionals.
---
This playground serves as a practical tool for illustrating vulnerabilities and teaching best practices in mobile app security 6.
Related Episodes


Episode 128: Web App Security with Bruce Sams
Answers 383 questions
Episode 173: Feature-Oriented Software Development with Sven Apel – Pt 2
Answers 383 questions
Episode 172: Feature-Oriented Software Development with Sven Apel – Pt 1
Answers 383 questions
Episode 197: Lars Vogel on Android
Answers 383 questions

Episode 180: Leading Agile Developers with Jurgen Appelo
Answers 383 questions

SE-Radio-Episode-309-Zane-Lackey-on-Application-Security
Answers 383 questions

SE-Radio Episode 330: Natalie Silvanovich on Attack Surface Reduction
Answers 383 questions

Episode 514: Vandana Verma on the Owasp Top 10
Answers 383 questions

SE Radio 642: Simon Wijckmans on Third-Party Browser Script Security
Answers 383 questions

Episode 198: Wil van der Aalst on Workflow Management Systems
Answers 383 questions

Episode 224: Sven Johann and Eberhard Wolff on Technical Debt
Answers 383 questions

SE Radio 614: Wouter Groeneveld on Creative Problem Solving for Software Development
Answers 383 questions

Episode 85: Web Services with Olaf Zimmermann
Answers 383 questions
Episode-467-Kim-Carter-on-Dynamic-Application-Security-Testing
Answers 383 questions

Episode 535: Dan Lorenc on Supply Chain Attacks
Answers 383 questions














