MitM Attack - Tagged - Security Boulevard The Home of the Security Bloggers Network Wed, 27 Mar 2024 17:14:37 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png MitM Attack - Tagged - Security Boulevard 32 32 133346385 Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data https://securityboulevard.com/2024/03/ghostbusters-facebook-theft-snapchat-richixbw/ Wed, 27 Mar 2024 17:14:37 +0000 https://securityboulevard.com/?p=2013174 Smokey Bear / This-is-fine crossover

Meta MITM IAAP SSL bump: Zuck ordered “Project Ghostbusters”—with criminal consequences, says class action lawsuit.

The post Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data appeared first on Security Boulevard.

]]>
2013174
The Limitations of Google Play Integrity API (ex SafetyNet) https://securityboulevard.com/2023/12/the-limitations-of-google-play-integrity-api-ex-safetynet/ Wed, 20 Dec 2023 17:10:26 +0000 https://blog.approov.io/limitations-of-google-play-integrity-api-ex-safetynet Statue of Android guy with PlayStore logo in grounds outside Google campus

This overview outlines the history and use of Google Play Integrity API and highlights some limitations. We also compare and contrast Google Play Integrity API with the comprehensive mobile security offered by Approov. The imminent deprecation of Google SafetyNet Attestation API means this is a good time for a comprehensive evaluation of solutions in this space.

The post The Limitations of Google Play Integrity API (ex SafetyNet) appeared first on Security Boulevard.

]]>
2002645
SSH FAIL: Terrapin Attack Smashes ‘Secure’ Shell Spec https://securityboulevard.com/2023/12/ssh-terrapin-attack-richixbw/ Wed, 20 Dec 2023 16:45:32 +0000 https://securityboulevard.com/?p=2002628 Line drawing of a diamondback terrapin

Testy Testudine: Lurking vuln in SSH spec means EVERY implementation must build patches.

The post SSH FAIL: Terrapin Attack Smashes ‘Secure’ Shell Spec appeared first on Security Boulevard.

]]>
2002628
The Security Threats to Mobile Crypto Apps and How to Protect Them https://securityboulevard.com/2023/07/the-security-threats-to-mobile-crypto-apps-and-how-to-protect-them/ Fri, 28 Jul 2023 08:04:49 +0000 https://blog.approov.io/the-security-threats-to-mobile-crypto-apps-and-how-to-protect-them Crypto coins on a phone with open Bianance app

The last year has not been great for crypto. Most crypto currencies, including Bitcoin, experienced significant loss of value, and we saw high profile exchanges like FTX collapse.  In addition, hackers were actively stealing crypto currency. The blockchain company Chainalysis calculated that $3.8bn was stolen by hackers in 2022.

The post The Security Threats to Mobile Crypto Apps and How to Protect Them appeared first on Security Boulevard.

]]>
1983262
‘BrutePrint’ Unlocks Android Phones — Chinese Researchers https://securityboulevard.com/2023/05/bruteprint-android-biometric-richixbw/ Wed, 24 May 2023 17:21:10 +0000 https://securityboulevard.com/?p=1976263

Or, at least, OLDER phones: SPI/TEE MITM FAIL

The post ‘BrutePrint’ Unlocks Android Phones — Chinese Researchers appeared first on Security Boulevard.

]]>
1976263
What is Runtime Application Self-Protection (RASP)? https://securityboulevard.com/2023/04/what-is-runtime-application-self-protection-rasp/ Thu, 06 Apr 2023 11:45:12 +0000 https://blog.approov.io/what-is-runtime-application-self-protection-rasp Cybersecurity concept with text What is Runtime Application Self-Protection

Runtime Application Self-Protection (RASP) is a security technology that is designed to protect applications from attacks while the application is running. It works by embedding a security mechanism directly into the application, which allows it to monitor the application's behavior and detect and prevent malicious activities in real-time.

The post What is Runtime Application Self-Protection (RASP)? appeared first on Security Boulevard.

]]>
1973098
Mobile App Security: Uncovering the Risks of Secret Theft at Runtime https://securityboulevard.com/2023/03/mobile-app-security-uncovering-the-risks-of-secret-theft-at-runtime/ Wed, 15 Mar 2023 16:26:00 +0000 https://blog.approov.io/mobile-app-security-uncovering-the-risks-of-secret-theft-at-runtime Cyber concept - coloured padlocks on digital background

This is our second blog highlighting the results of the Approov Threat Lab Report.

The post Mobile App Security: Uncovering the Risks of Secret Theft at Runtime appeared first on Security Boulevard.

]]>
1968577
Do You Want to Know a Secret? Just Take a Look Inside Top Finance Apps https://securityboulevard.com/2023/03/do-you-want-to-know-a-secret-just-take-a-look-inside-top-finance-apps/ Tue, 07 Mar 2023 17:54:58 +0000 https://blog.approov.io/do-you-want-to-know-a-secret-just-take-a-look-inside-the-top-finance-apps Secrets Concept; Dictionary definition of secret

Financial apps have access to valuable and sensitive personal data, so you would think mobile app security would be top-of-mind for financial institutions. But is it? 

The post Do You Want to Know a Secret? Just Take a Look Inside Top Finance Apps appeared first on Security Boulevard.

]]>
1966933
Is Certificate Pinning Worth it? https://securityboulevard.com/2022/11/is-certificate-pinning-worth-it/ Thu, 24 Nov 2022 10:28:16 +0000 https://blog.approov.io/is-certificate-pinning-worth-it Pinning concept; overhead view of yellow and white push pins on a blue background

In a word - yes; when implemented correctly, certificate pinning is an effective method for securing mobile application traffic by restricting the accepted certificates to just those you are willing to trust. In its most secure manifestation, this trust sits outside the standard TLS certificate store managed by the device.

The post Is Certificate Pinning Worth it? appeared first on Security Boulevard.

]]>
1947054
What is SafetyNet and How Does it Improve Android Security? https://securityboulevard.com/2022/11/what-is-safetynet-and-how-does-it-improve-android-security/ Mon, 21 Nov 2022 10:55:40 +0000 https://blog.approov.io/what-is-safetynet-and-how-does-it-improve-android-security What is SafetyNet and how does it improve Android security? We look at the security that Google SafetyNet brings and how that will change as it is replaced by Google’s Play Integrity API.

The Google SafetyNet API is a service for verifying the trustworthiness of the Android operating system on a given device mobile device. In this article we will look at the security it brings and how that will change as it is replaced by Google’s Play Integrity API.

The post What is SafetyNet and How Does it Improve Android Security? appeared first on Security Boulevard.

]]>
1946586