Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Removing Secrets to Make Mobile Apps More MASVS-Secure

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines ways to protect mobile apps from exposed secrets and attacks on their communication channels. It covers static analysis, obfuscation, Play Integrity, certificate pinning, user authentication, and remote secret storage.

Syllabus

Intro
Danger - Hardcoded API Keys
Mobile Attack Surfaces
Attack: Static Analysis
Defense: Obfuscation
Defense: Play Integrity
Attack: Manipulator in the Middle
Defense: Certificate Pinning
Attack: Bypass Certificate Pinning
Defense: Harden Channel
Hide & Seek Observations
How Do We Authenticate Our Users?
Design Objectives
Proposed Architecture
Making a 1st Party API Call
Changing the Signing Secret
Remote Secrets Storage
Managing Certificate Pinning
Signing a Message
Updating Security Live
MASVS Resilience
App Auth as a Service

Taught by

OWASP Foundation

Reviews

Start your review of Removing Secrets to Make Mobile Apps More MASVS-Secure

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.