Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
iOS Security - Hacking iOS Apps
Search
Bruno Rocha
June 11, 2017
Technology
22
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
iOS Security - Hacking iOS Apps
TDC 2017
Bruno Rocha
June 11, 2017
More Decks by Bruno Rocha
See All by Bruno Rocha
BuckOutsideValley.pdf
rockbruno
1
110
Avoiding Release Anxiety
rockbruno
0
39
Creating Scalable iOS Apps
rockbruno
0
20
Other Decks in Technology
See All in Technology
手を動かして実感する、Kiro が変える開発体験
inariku
0
260
事業課題から技術的負債に向き合う
sansantech
PRO
2
2.3k
おい、エージェントを使って終わらせろ
nwiizo
3
910
2026-09-18 gotanda.sre Terraformで複数環境作ったり、複数Stateに分割したりそれとTerragrunt / Terraform multi envs and multi states
masasuzu
4
720
C#未経験の僕がAIに読めるコードを書かせるまで
maguroalternative
0
270
AI coding 整合正規方法
philipz
0
550
AIで社員の自主発信に広報目線を組み込む
_mossann_t
0
140
Claude Codeを「使うほど育つ」AI秘書にするノウハウ
minorun365
PRO
33
32k
Why Agent Cost Needs Observability
nttcom
0
150
品質と信頼性を地続きにする
grimoh
2
1k
データ_AIの事業の勝敗をわけるもの
nek0128
1
480
beyond jj: config & tools ecosystem
indirect
0
6k
Featured
See All Featured
My Coaching Mixtape
mlcsv
0
320
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
2
440
We Are The Robots
honzajavorek
0
380
How STYLIGHT went responsive
nonsquared
100
6.3k
Optimising Largest Contentful Paint
csswizardry
37
4k
Designing for humans not robots
tammielis
254
26k
The Web Performance Landscape in 2024 [PerfNow 2024]
tammyeverts
12
1.3k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
21
1.6k
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
260
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
900
Designing for Performance
lara
611
70k
SEO Brein meetup: CTRL+C is not how to scale international SEO
lindahogenes
2
2.9k
Transcript
iOS Security Bruno Rocha iOS Developer @ Movile
Bad people
Crypto keys in NSUserDefaults/Keychain Secret API Keys in the Info.plist
or hardcoded CoreData/SQLite with sensitive data var isSubscribed: Bool
NSUserDefaults - Documents folder, not encrypted CoreData - Documents folder,
not encrypted Info.plist - Exposed in your .ipa/.app Keychain - Encrypted, but exploitable NSKeyedArchiver - A plist in hex format
None
None
var isSubscribed: Bool { let subscription = getSubscription() return subscription.isExpired
== false } var swizzled__isSubscribed: Bool { return true }
None
Demo 1: Insecure Data Storages
Protecting apps from Storage Attacks • Encrypt/Encode data before saving/
hardcoding (Careful! This will not prevent attacks, only slow them down.) • Treat critical data (like secret API keys) server-side if possible • Open Source “String obfuscation" libs: Hackers have Google too.
Demo 2: Runtime Manipulation
Protecting apps from Runtime Manipulation Important logic should be treated/
checked server-side! (eg: API Tokens)
Protecting apps from Runtime Manipulation
Protecting apps from Runtime Manipulation
What about the real world?