Application development
Pages
Page 5 of 16
Questions for application developers
For anyone procuring an application built by a third party, you can ask developers the example questions below. Their answers will help you gain more (or less) confidence about the security of their products.
The most thorough way to assess an application before deploying it would be to conduct a full source code review to ensure it meets the security recommendations and contains no malicious or unwanted functionality. Unfortunately, for the majority of third party applications, this will be infeasible or impossible. However, the responses from the third party should help provide confidence that the application is well written and likely to protect information properly.
2.1 Secure data storage
The following questions will help you establish how confident you can be that an Android application stores sensitive data securely.
| Questions | What to look for in answers |
|---|---|
| What is the flow of data through the application - source(s), storage, processing, and transmission? | Answers should cover all forms of input including data entered by the user, network requests, and inter-process communication. |
| How is sensitive data stored on the device? | Data should be stored in a location that cannot be accessed by other applications on the device. Data should not be accessible to other applications on the device through inter-process communication provided by the application, e.g. content providers. Data should be encrypted when stored on the device. Encryption of sensitive data should be performed using a key that is not stored on the device. Either the key is derived from user input, or returned from a server following authentication. |
| What device or user credentials are being stored? Are these stored in the Android Keystore? What key is used? | If certificates are stored on the device then they should be stored using the Android Keystore. |
| Are cloud services used by the app? What data is stored there? How is it protected in transit? | Sensitive data should not be transmitted to unassured cloud services. If non-sensitive data is transmitted, or data is transmitted to accredited data centres then questions should be asked about data in transit protection. |
2.2 Secure data transmission
The following questions will help you gain confidence in how Android applications transmit sensitive data securely:
| Questions | What to look for in answers |
|---|---|
| Is transmitted and received data protected by cryptographic means, using well-defined protocols? If not, why not? | Mutually authenticated TLS, Secure Chorus, or other mutually authenticated secure transport should be used to protect information as it travels between the device and other resources. This should be answered specifically for each service the application communicates with to send and receive sensitive information. |
2.3 IPC mechanisms
The following questions will help you gain confidence in how Android applications share sensitive data securely.
| Questions | What to look for in answers |
|---|---|
| Are any URL schemes or exported intents declared or handled? What actions can these invoke? | Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |
| Are there any exported content or file providers? Is any sensitive data accessible? Are there any bespoke implementations for querying, updating, or deleting data in the provider? What custom actions are performed? Are prepared statements used for querying the provider? | Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |
| Is input from statically or dynamically registered broadcast receivers treated as untrusted? | Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |
| Can other applications cause the application to perform a malicious action on its behalf, or request access to sensitive data? | Interactions with other applications should be limited to only those essential for the application to function. |
2.4 Binary protection
The following questions will help you gain confidence in how Android applications protect their data within a binary.
| Questions | What to look for in answers |
|---|---|
| Is the application compiled in release mode and has all debug information been removed from the binary? | All debugging information should have been removed from the application. |
| Does the application make use of obfuscated code or other protections against reverse engineering? | Code obfuscation can be used to help hinder reverse engineering of applications. However, application code should not include any sensitive data. |
| Does the application make use of binary anti-tamper or anti-hooking protections? | These protections improve the security of the application, if they are not used reasons should be given to suitably explain why. |
| Is the application compiled to be debuggable? | The debuggable flag in the manifest file should be set to false. |
2.5 Server side controls
The following questions will help you gain confidence in how Android applications protect their data on the server side.
| Questions | What to look for in answers |
|---|---|
| If the application connects to remote services to access sensitive data, how can that access be revoked? How long does that revocation take? What is the window of opportunity for theft? | Assessors should be aware of the length of window of opportunity for data theft. |
2.6 Client side controls
The following questions are will help you gain confidence in how Android applications protect their data on the client side.
| Questions | What to look for in answers |
|---|---|
| Does the application make use of Web Views? Is JavaScript enabled within the WebView? | By default, Web Views support JavaScript. Therefore, where it is not needed, we recommend that this is explicitly disabled to protect against malicious JavaScript injected into the Web View. |
| Are there any JavaScript bridges implemented within the application? | JavaScript bridges may significantly increase the overall attack surface of the application if implemented without care. |
2.7 Other
| Questions | What to look for in answers |
|---|---|
| Does the application implement root detection, and if so how? | Root detection can never be completely protected against, but the more advanced the detection, the more effort is required to bypass it. Google’s SafetyNet Attestation API can be used to help detect rooting. |
| Are applications allowed to run in an Android Emulator when in production build? | Applications that can run in the emulator are easier to reverse engineer. The sandboxed directory of the application can be inspected and manipulated, allowing for greater understanding of the security state of the application. Additionally, the simulator may contain additional testing functionality or have more verbose logging. |
| How is session timeout managed? | The application should include a timeout following inactivity by the user. |
| How is copy and paste managed? | Whichever solution is used to manage copy and paste, the appropriate risk owner should understand and accept how data could leak. |
| Is potentially sensitive data displayed within the screenshot when the application is backgrounded? Are there configuration options which may cause the security of the solution to be weakened or disabled? | Backgrounding should be performed to ensure that sensitive data is not leaked in screenshots taken of apps for task switching. |
| What configuration options are available to end users, and what is the impact to the solution’s security if the user were to change those settings? | Configuration options that users are able to change should not prevent the application from working correctly (or affect the application's security features). |
| Are there debug messages logged to the console output? | No debugging information should be logged to console. |


