Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390 @SecurityWeekly
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390  @SecurityWeekly
Uploaded July 2026 | Updated September 2026, 2 weeks ago
Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust.

Segment Resources:
- https://hubs.la/Q04jLKj70
- mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering
- owasp.org/API-Security/editions/2023/en/0x00-header

This segment is sponsored by Guardsquare. Visit securityweekly.com/guardsquare to learn more about them!

Visit securityweekly.com/asw for all the latest episodes!

Show Notes: securityweekly.com/asw-390

00:00:00 Episode 390: Mobile App Security Introduction
00:02:01 Understanding Reverse Engineering and Tampering Risks
00:05:40 Combating Account Takeover and KYC Fraud
00:09:20 Implementing Layered Mobile App Defenses
00:13:40 How LLMs Change Attacker Efficiency
00:15:47 Where to Place Mobile App Defenses
00:19:07 Industry-Specific Mobile App Security Concerns
00:22:28 Balancing Security with User Privacy Needs
00:27:01 Compiler-Level Protection for Mobile Applications
00:30:54 Server-Side Attestation for Enhanced Trust
00:35:56 Mobile OS and Shared Security Model
00:40:00 Underappreciated Mobile Threats and Evolving Tools
00:43:20 Final Thoughts on Application Security
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Security Tools Are Breaking SOCsAI Becomes The Supply ChainThe Hidden Risk of Patch PrioritiesAI Agents Escaped the Evaluation EnvironmentAI Is Reviving Anomaly DetectionSmart Toilets: Health Insights or Data Concerns?When AI Chooses Your VendorWhen Security Benchmarks Break SystemsWhat Counts as a Crypto Security?When AI Attacks Critical InfrastructureRogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603
Security Weekly - A CRA Resource |

Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER