{"product_id":"ios-application-security-isbn-9781593276010","title":"iOS Application Security","description":"Eliminating security holes in iOS apps is critical for any developer who wants to protect their users from the bad guys. In \u003ci\u003eiOS Application Security\u003c\/i\u003e, mobile security expert David Thiel reveals common iOS coding mistakes that create serious security problems and shows you how to find and fix them.\u003cbr\u003e\u003cbr\u003eAfter a crash course on iOS application structure and Objective-C design patterns, you’ll move on to spotting bad code and plugging the holes. You’ll learn about:\u003cbr\u003e–The iOS security model and the limits of its built-in protections\u003cbr\u003e–The myriad ways sensitive data can leak into places it shouldn’t, such as through the pasteboard\u003cbr\u003e–How to implement encryption with the Keychain, the Data Protection API, and CommonCrypto\u003cbr\u003e–Legacy flaws from C that still cause problems in modern iOS applications\u003cbr\u003e–Privacy issues related to gathering user data and how to mitigate potential pitfalls\u003cbr\u003e\u003cbr\u003eDon’t let your app’s security leak become another headline. Whether you’re looking to bolster your app’s defenses or hunting bugs in other people’s code, \u003ci\u003eiOS Application Security\u003c\/i\u003e will help you get the job done well.Introduction\u003cbr\u003ePART I: IOS FUNDAMENTALS \u003cbr\u003eChapter 1: The iOS Security Model\u003cbr\u003eChapter 2: Objective-C for the Lazy\u003cbr\u003eChapter 3: iOS Application Anatomy\u003cbr\u003ePART II: SECURITY TESTING\u003cbr\u003eChapter 4: Building Your Test Platform \u003cbr\u003eChapter 5: Debugging with lldb and Friends\u003cbr\u003eChapter 6: Black-Box Testing\u003cbr\u003ePART III: SECURITY QUIRKS OF THE COCOA API\u003cbr\u003eChapter 7: iOS Networking\u003cbr\u003eChapter 8: Interprocess Communication\u003cbr\u003eChapter 9: iOS-Targeted Web Apps\u003cbr\u003eChapter 10: Data Leakage\u003cbr\u003eChapter 11: Legacy Issues and Baggage from C\u003cbr\u003eChapter 12: Injection Attacks\u003cbr\u003ePART IV: KEEPING DATA SAFE\u003cbr\u003eChapter 13: Encryption and Authentication\u003cbr\u003eChapter 14: Mobile Privacy Concerns“The book is strongly recommended for all iOS app developers, especially for those who use the Objective-C programming language.”\u003cbr\u003e\u003cb\u003e—Computing Reviews\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e“In summary, this is a book that every iOS developer needs to read and then act on. The next time you see an app that leaks private data everywhere, is vulnerable to a whole host of injection attacks, and uses crypto like it’s 1995, ask them why they didn’t consult this book before shipping.”\u003cbr\u003e\u003cb\u003e—;login:\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e“\u003ci\u003eiOS Application Security\u003c\/i\u003e offers an excellent foundation for anyone interested in ethical hacking on mobile platforms. This is going to be a growing sector of the penetration testing industry, as mobile devices assume an ever-greater importance in corporate IT estates.\"\u003cbr\u003e\u003cb\u003e—Network Security Newsletter\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"Worthy read and covers a lot of ground in 200ish pages. Well recommended.\"\u003cbr\u003e\u003cb\u003e—Michael Howard, author of Writing Secure Code\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"A major asset to any iOS developer who wants to ensure his app's ability to protect a user's data. I would highly recommend anyone interested in the field of iOS app security to take a close look at \u003ci\u003eiOS Application Security\u003c\/i\u003e.\"\u003cbr\u003e\u003cb\u003e—MacTrast\u003cbr\u003e\u003c\/b\u003e\u003cb\u003eDavid Thiel\u003c\/b\u003e has nearly 20 years of computer security experience. His research and book \u003ci\u003eMobile Application Security\u003c\/i\u003e (McGraw-Hill) helped launch the field of iOS application security, and he has presented his work at security conferences like Black Hat and DEF CON. An application security consultant for years at iSEC Partners, Thiel now works for the Internet.org Connectivity Lab.","brand":"No Starch Press","offers":[{"title":"Default Title","offer_id":46300417065189,"sku":"NP9781593276010","price":49.95,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781593276010.jpg?v=1767730172","url":"https:\/\/k12savings.com\/products\/ios-application-security-isbn-9781593276010","provider":"K12savings","version":"1.0","type":"link"}