The digital forensics and security consulting firm viaForensics just published a report that outlines 40 best practices for developing secure mobile applications. This free report is based on the company’s expertise in testing hundreds of mobile apps for vulnerabilities. See what viaForensics has to say about your favorite mobile apps.
In last week’s article, “Ensuring that mobile applications are truly secure,” I wrote about the appSecure service from viaForensics that thoroughly tests mobile applications to see if they have vulnerabilities that put private or sensitive data at risk. Companies that want to distribute mobile productivity apps to employees or customers are the typical users of this service. In a weeks-long engagement, viaForensics attacks the application from every angle to see if it can get to sensitive data on the device or during any part of the application’s processes.
The unique aspect of this testing service is that viaForensics uses forensic techniques to analyze the application. Researchers look for any trace of vulnerable data that is left behind after the application has been used. For instance, sensitive account information may be left in the long-term memory of the mobile device, despite the app developers’ efforts to wipe the data.
MORE: Scary times ahead for smartphone vendors, says analyst
Over the course of several years, the viaForensics research team has learned a lot about the operations of mobile devices and the applications that run on them. This team has learned the idiosyncrasies of mobile operating systems like Apple iOS and Google Android, as well as the base level hardware platforms from virtually every device manufacturer. They’ve learned the most likely ways that mobile apps will be vulnerable to compromise, and how to plug those vulnerabilities.
Now viaForensics wants to share some of this knowledge with you. The company has just published 42+ Secure Mobile Development Best Practices to help app developers avoid common problems and create more secure applications for the iOS and Android platforms. Even if you don’t develop mobile applications, it’s worth reading the mobile security primer to understand the anatomy of a mobile attack and the potential attack vectors including the device, the network and the back-end data center.
Understanding how attacks happen can be helpful as your company develops and deploys its bring-your-own-device (BYOD) policies and mobile device management (MDM) solutions. For example, the Android OS is particularly vulnerable to drive-by downloads, where a website visit causes a download to occur without user knowledge, or by tricking the user with a deceptive prompt. The download can be a malicious app, and the user then may be prompted automatically by the device to install the app. When Android devices are set to allow apps from “unknown sources” the installation is allowed. As a precaution, personally owned Android devices that are permitted to connect to your network should have this installation setting flipped to “off.”
The report provides 49 detailed sections on a wide range of topics such as:
• Beware of the keyboard cache
• Implement secure data storage
• How to do tamper checking
• Understand secure deletion of data
• Implementing enhanced/two-factor authentication
• And much more …
This report is one way you can benefit from viaForensics’ work for free. A second way is to visit the appWatchdog list to learn about security vulnerabilities in some of the most common or popular mobile applications.
appWatchdog is a free service that is a by-product of the extensive testing done through the appSecure service. The forensic investigators apply their expertise to publicly available mobile applications that are popular with consumers or that they, the researchers, have a personal interest in. The intent is to provide information consumers can use to protect their identity and financial information.
The application developers typically are not involved in an appWatchdog review. Consequently, the testing applied to an application isn’t as extensive as what’s done in an appSecure engagement. However, the researchers do look at the application from a forensics point of view to determine if using the application causes any trace of sensitive data to be “left behind” and accessible by unauthorized users or hackers. They apply more than two dozen specific tests and report their findings on the appWatchdog list. You can see the particular areas where an application, in viaForensics’ opinion, has failed to adequately protect private or sensitive data.
According to Andrew Hoog, chief investigative officer and co-founder of viaForensics, it’s challenging to write secure mobile applications. Mobile platforms such as tablets and smartphones are quite different from traditional platforms. viaForensics is hoping to educate (and certify) developers so that they create secure mobile apps that don’t put consumers and businesses at risk.
Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.
______________________________________________________________
About Essential Solutions Corp:
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




