After scanning over a million apps — 3 things Mobile App Devs need to know about App Security

Written by proxyblue | Published 2020/02/21
Tech Story Tags: security | infosec | mobile-app-development | web-development | development

TLDR The content of this blog was presented at /dev/world 2017. Many of the points are still very relevant, but the data will be a bit old. Around 65-70% of all public apps are currently not implementing Application Transport Security correctly by implementing NSAllowsArbitaryLoads. Around 100,000 apps are potentially susceptible to downgrade attacks. The worst part: You would never know if the app is not using HTTPS or there’s no.There are no. apps that do not implement HTTPS for a query that looks like it involves a password.via the TL;DR App

no story

Written by proxyblue | Developer. Security Guy. Currently reading the internet. ❤️ innovation and NeuroTech. @proxyblue
Published by HackerNoon on 2020/02/21