Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

Ted Eull

How bad OAuth 2.0 implementation sabotages mobile app security

By / November 4, 2017 / Comments Off on How bad OAuth 2.0 implementation sabotages mobile app security

Researchers unveiled a startling discovery this week: 41 percent of the most popular Android apps that implement OAuth 2.0 allow an attacker to remotely impersonate any user account, access personal information from within the app, and make in-app purchases on the user’s dime.  In this post I explain OAuth 2.0 and how it affects mobile app security and risk.

Android Instant Apps: The security jury is out

By / May 19, 2017 / Comments Off on Android Instant Apps: The security jury is out

The convenience of Instant Apps is appealing, but attackers will view it as a shiny new attack vector, and for me the security jury is still out.