Research

Application security testing, analysis, and metrics

Mobile App Security

Neil MacDonald at Gartner asks the question, “Why Don’t Mobile Application Stores Require Security Testing?”

I couldn’t agree more that we may be missing an opportunity to bring whitelisting to these new important mobile platforms. We need to leave the “detect and revoke” mentality of the PC world behind as we move to new platforms. Attackers are able to game the PC antivirus model by continuously flooding the software ecosystem with new unknown malware. The attackers will win in the mobile world too if we don’t change it. The mobile app store is a form of whitelisting that can assure the security of an entire platform if the whitelisting means something. That is if the apps are tested for security before being published.

Veracode is being asked by large financial organizations to build security testing into internal mobile app stores. There is obviously a desire for security screened applications in the corporate and government world. Why not just scan once at the platform provider’s app store and give the benefits to all?

Veracode researcher Tyler Shields is presenting 2/7/2010 at Shmoocon on Blackberry malicious mobile code. The presentation and sample code will be available here.

Veracode Security Solutions
Veracode Security Threat Guides

Written by:

2 Comments »

[...] Wysopal formerly of L0pht and @stake summarizes the situation facing mobile phone users the best. (http://www.veracode.com/blog/2010/02/mobile-app-security/) “We need to leave the “detect and revoke” mentality of the PC world behind as we move to new [...]

Pingback by Those Who Cannot Remember the Past are Condemned to Repeat it — March 1, 2010 @ 10:54 am

Thanks for highlighting the importance of security testing. We need to be aware of security loopholes from the test results and provide better security to end users.

Comment by Personnel Security — June 24, 2010 @ 9:34 am

RSS feed for comments on this post. TrackBack URI

Leave a comment


Mobile Security

Sql Injection

cyber security

Categories

Archive

Powered by WordPress