Devil in the Details: A Reverse Engineering Campaign Across 30 Financial Services Mobile Apps

No ratings

Presented at InfoSecurityEurope 2019 by

Following a six-week research study I performed into reverse engineering financial services mobile apps, I am on a world tour unveiling my vulnerability findings in retail banking, cryptocurrency wallets, stock trading, auto insurance, health insurance, payment processors, P2P money transfer, and HSA banking apps that included both US and European FinServe and FinTech companies. The vulnerabilities I'll be unveiling underscores a systemic problem that ultimately lead to API, cloud service provider, SaaS, and payment processor security breaches used by these mobile apps as a result of insecure coding practices. Join me as I unveil my vulnerability findings in part 1 of this 3 part series of vulnerability research.Learning Outcomes:Development teams, cybersecurity engineers, chief information security officers, and other senior business leaders will leave better-informed on the threats to their APIs and third-party suppliers as a result of poor secure coding practices in their mobile apps and how they can address them.