Application development
Pages
Page 10 of 16
Questions for application developers
For anyone procuring an application built by a third party, you can ask developers the example questions below. Their answers will help you gain more (or less) confidence about the security of their products.
The most thorough way to assess an application before deploying it would be to conduct a full source code review to ensure it meets the security recommendations and contains no malicious or unwanted functionality. Unfortunately, for the majority of third party applications, this will be infeasible or impossible. However, the responses from the third party should help provide confidence that the application is well written and likely to protect information properly.
2.1 Secure data storage
The following questions will help you gain confidence that an iOS application stores sensitive data securely:
| Questions | What to look for in answers |
|---|---|
| What is the flow of data through the application - source(s), storage, processing and transmission? | Answers should cover all forms of input including data entered by the user, network requests, and inter-process communication. |
| Which data protection classes are used to store the various data types on the device? | Data should be stored using Data should be stored using All other data should be stored using Answers to this question should generally be provided on a per-file or per-file-type basis. The answer “All data is stored using Class C” is not acceptable. |
| What device or user credentials are being stored? Are these stored in the Keychain? Which Keychain protection class is used? | As with the Data Protection classes above, the appropriate Keychain classes should also be used to protect key material based on time of need. |
2.2 Secure data transmission
The following questions will help you gain confidence that an iOS application transmits sensitive data securely:
| Questions | What to look for in answers |
|---|---|
| Is transmitted and received data protected by cryptographic means, using well-defined protocols? If not, why not? | Mutually authenticated TLS, Secure Chorus, or other mutually authenticated secure transport should be used to protect information as it travels between the device and other resources. This should be answered specifically for each service the application communicates with to send and receive sensitive information. |
| Is App Transport Security enabled and are there any exceptions for certain domains? If so why? | App Transport Security should be enabled and exception domains should be avoided where possible. |
2.3 IPC mechanisms
The following questions will help you gain confidence that an iOS application shares sensitive data securely:
| Questions | What to look for in answers |
|---|---|
| Are any URL schemes or Universal Links declared or handled by the application? What actions can these invoke? | Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |
| Can other applications cause the application to perform a malicious action or request on its behalf? | Interactions with other applications should be limited to only those essential for the application to function. |
2.4 Binary protection
The following questions will help you gain confidence that an iOS application protects its data within a binary:
| Questions | What to look for in answers |
|---|---|
| Is the application compiled with Position Independent Execution (PIE)? | PIE should be used to help prevent exploitation of vulnerabilities in applications. |
| Is the application compiled with Automatic Reference Counting (ARC)? | ARC should be used for automatic object garbage collection to avoid developers manually allocating and freeing application memory. |
| Is the application compiled in release mode and has all debug information been removed from the binary? | All debugging information should have been removed from the application. |
| Does the application make use of binary anti-tamper or anti-hooking protections? | These protections improve the security of the application. If they are not used, reasons should be given to suitably explain why. |
| Does the application make use of obfuscated code or other protections against reverse engineering? | Code obfuscation can be used to help hinder reverse engineering of applications. However, application code should not include any sensitive data. |
2.5 Server side controls
The following questions will help you gain confidence that an iOS application protects its data on the server side:
| Questions | What to look for in answers |
|---|---|
| If the application connects to remote services to access sensitive data, how can that access be revoked? How long does that revocation take? What is the window of opportunity for theft? | Assessors should be aware of the length of window of opportunity for data theft. |
2.6 Client side controls
The following questions will help you gain confidence that an iOS application protects its data on the client side:
| Questions | What to look for in answers |
|---|---|
| Does the application make use of iOS Web Views? Is JavaScript enabled within the Web View? | By default iOS Web Views support JavaScript. Therefore - where it is not needed - we recommend that this is explicitly disabled to protect against malicious JavaScript if injected into the Web View. |
| Are there any JavaScript bridges implemented within the application? | Assessors should be aware of the risks of JavaScript bridges and the attack surface exposed. |
2.7 Other
These additional questions will help you gain confidence in how an iOS application protects itself.
| Questions | What to look for in answers |
|---|---|
| Does the application implement jailbreak detection, and if so how? | Jailbreaking can never be completely protected against, but the more advanced the detection the more effort is required to bypass it. Mechanisms for detecting jailbroken devices range from checking for the installation of known jailbroken applications such as Cydia, through to technologies that will attempt to detect if a third party process has hooked into the application. |
| How is copy and paste managed? | Whichever solution is used to manage copy and paste, the appropriate risk owner should understand how data could leak and accept the risk. Is the Universal Clipboard being used? Have controls been implemented to protect against sensitive information being shared using device Handoff? |
| Is potentially sensitive data masked-off on screen when the application is sent to the background? | This should be performed to ensure that sensitive data is not leaked in screenshots taken of apps for task switching. |
| What configuration options are available to end users, and what is the impact to the solution’s security if the user were to change those settings? | Some user configuration options may cause the security of the solution to be weakened or disabled. |
| Has all debugging output been removed from the binary? Are there no debug messages logged to the console output? | All debugging information should have been removed from the application. |
| Does the application make use of extensions? Have they been subject to the same security controls as the main application? | Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |


