Best Practices
Mobile app security professionals who connect and engage with the broader mobile appsec community can amplify their efforts and learn from each other. Combined, the NowSecure services team members have pen tested thousands of mobile apps. They share three key best practices for mobile app pen testing that practitioners can adopt to meet their organizations’ needs.
Looking to build some mobile application security muscle? Staffing a strong team begins with identifying the right blend of skills and experience and pairing those people with appropriate tools and processes.
With most online traffic shifting to mobile, organizations are at risk of data loss due to risky mobile apps that have security and privacy vulnerabilities. Consult this infographic to see potential threats in mobile app code functionality, data at rest and data in motion and how to identify them with mobile appsec testing.
Nearly all mobile apps interact with backend systems and require secure communications. One best practice for developers to safeguard network communications is to implement certificate pinning in their apps. Certificate pinning protects against attackers intercepting sensitive data via man-in-the-middle (MiTM) attacks. Learn more here.
Although Mobile Threat Defense (MTD) has captured attention from regulated industries and government, it doesn’t provide the price/performance value to justify investment. Here’s why mobile app vetting offers a stronger, cost-effective approach to managing mobile risk.
Because NowSecure was founded as a mobile application forensics company a decade ago, penetration testing is built into our DNA. We’ve tested thousands of Android and iOS apps on behalf of our customers, uncovered some scary vulnerabilities and helped customers improve the security of their mobile apps. The following is the third installment of an […]
Mobile app developers often use deep links to improve the user experience and engagement by helping users navigate from the web to their app. However, our security testing has found an easily exploitable vulnerability when deep links are used incorrectly for authorization purposes. This blog will explain how this vulnerability can be exploited and how to safeguard your app by using the more secure version of deep links, App Links.
While mobile app security testing is fairly new, we still see a considerable share of BS from vendors. Inspired by a similar DoD document for Agile, we created our own list of crucial capabilities and key questions to ask prospective tool vendors.
As DevSecOps teams incorporate mobile application security testing into the build pipeline, they need the process to be painless. Follow these smart strategies for selecting and implementing an automated testing tool that keeps pace with the mobile app release cycle and helps ensure security, compliance and privacy.
Popular low or no-code mobile application development platforms empower new ranks of citizen developers. However, the tools can also shortchange application security and must be properly tested before the apps are rolled out. Learn some best practices for safely incorporating these app dev platforms into your organization.