RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Friday, September 4, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Reader Forum: 5 common mobile security vulnerabilities
OpinionReader Forum

Reader Forum: 5 common mobile security vulnerabilities

by Reader Forum June 27, 2016
written by Reader Forum June 27, 2016 Share
LinkedinEmail
Share 0LinkedinEmail
NFV
133

Kony lays out the 5 most common mobile security vulnerabilities and ways mobile application developers can surmount those issues

With the increasing adoption of mobile application development among both small and large organizations, security is a top concern – but are businesses focusing on the right issues? Are developers approaching potential vulnerabilities in the right way to ensure data safety and maintenance of a business’s mobile strategy? This article takes a look at misconceptions about the five most common mobile security vulnerabilities and how they can be addressed.

Weak server-side controls

This issue encompasses almost everything a mobile application can do badly that does not take place on the phone, such as the related backend services and infrastructure that support the mobile environment.
Biggest misconception
It is simply not true that application programming interfaces consumed by mobile devices are only consumed by mobile devices. The reality is most API services on the web are accessible even without the mobile app they were created for. Hackers can sniff out the wireless network or perform a man-in-the-middle attack to discover the API calls being made, modify them and attack the API directly by invoking the calls without the mobile app. Generally, the industry does a bad job of making sure that APIs are restricted to their intended mobile applications.
The solution
Secure coding and configuration practices must be used on the server side of the mobile application. Specifically, the API should securely verify the identity and permission of the caller.

Insufficient transport layer protection

Biggest misconception
Using Secure Sockets Layer/Transport Layer Security on a mobile app makes it secure. The reality is that man-in-the-middle attacks (even on SSL/TLS) are a lot easier than you think – especially if the attacker has physical access to the mobile device.
The solution
The mobile application should use certificate pinning or Hypertext Transfer Protocol public key pinning to prevent man-in-the-middle attacks. It can also use two-way authentication to gain nonrepudiation and authentication capability of both the server and client. Make sure all connections to the servers are encrypted (if applicable) using best practice configurations (i.e. currently TLS 1.2), do not accept user-accepted certificates as authorities, and make sure your SSL certificates are up-to-date and signed by a trusted certificate authority.

Unintended data leakage

Biggest misconception
It’s important to focus on protecting data from typical mobile app use cases. But the truth is there are a lot of other ways the data gets viewed, copied, cached, screen captured, backed up, logged, etc., that likely have not been considered, putting the data at risk. Even a custom keyboard app within the app could be “key logging” information without your knowledge.
The solution
Consider that the native mobile operating system often provides ways for users to copy/paste data, take screen captures with a mobile device, create mobile data backups using custom keyboards, and collect analytics with third-party apps. Consider the data and risk presented by these various scenarios and determine if it’s acceptable for the mobile app. If not, explicitly prevent these capabilities from within the mobile application or through control of the device with an Mobile Device Management/Mobile Application Management solution.

Poor authentication and authorization

Biggest misconception at authentication
The mobile app user who authenticated once before is still the same person. The user could have had their mobile device lost/stolen or had their credentials stolen from an insecure wireless network. Should the thief still be able to access his account information in his mobile banking app? Definitely not.
Biggest misconception at authorization
Assuming users are automatically authorized to do anything at any time because they have been authenticated. Consider a paid mobile app in which a user has cancelled his subscription, but because a persistent session had previously been authorized within the mobile app the user can continue to use the paid app for free. No hacking required.
The solution
Authenticate and reauthenticate the user periodically and before any sensitive action is performed. Authorize every request every time.

Lack of binary protections

Biggest misconception
Your mobile app is not at risk of being reverse-engineered, analyzed or tampered with. Believing you don’t need to protect your application binaries.
The solution
Protection varies by threat and mobile platform. Ensure your application is protected at runtime against analysis, monitoring and code injection. Also ensure that the mobile source code is encrypted and obfuscated. Integrity checks can help prevent modification of resources and source code. Preventing the mobile app from running on an insecure device, such as a rooted Android or jail-broken iPhone, also will help.
As more businesses turn to mobility, hackers are becoming smarter and more creative. It’s never been more important for  information technology professionals and developers to keep these mobile security vulnerabilities in mind in order to protect the integrity of their businesses and the bottom line.
Editor’s Note: In an attempt to broaden our interaction with our readers we have created this Reader Forum for those with something meaningful to say to the wireless industry. We want to keep this as open as possible, but we maintain some editorial control to keep it free of commercials or attacks. Please send along submissions for this section to our editors at: [email protected].

You Might Also Like
  • Distributed AI inference is redrawing the network map (Reader Forum)
  • LoRaWAN is powering the next phase of IoT (Reader Forum)
  • How space traffic management can save our satellites (Reader Forum)
  • Thursday (telco diary) | Ghosts in the machine – Wanted: more humans to build AI
  • Wednesday (telco diary) | Smells like team spirit – and that tech-bro Musk
  • Tuesday (telco diary) | About open RAN, c/o Dell’Oro…

Table of Contents

  • Kony lays out the 5 most common mobile security vulnerabilities and ways mobile application developers can surmount those issues
  • Weak server-side controls
  • Insufficient transport layer protection
  • Unintended data leakage
  • Poor authentication and authorization
  • Lack of binary protections
Share 0 LinkedinEmail
Reader Forum

Submit Reader Forum articles to [email protected]. Articles submitted to RCR Wireless News become property of RCR Wireless News and will be subject to editorial review and copy edit. Posting of submitted Reader Forum articles shall be at RCR Wireless News sole discretion.

previous post
Reader Forum: 7 tips for rural carriers in battling Verizon, AT&T, T-Mobile and Sprint
next post
Indian government sets reserve for new spectrum auction

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Report: Rethinking the RAN

  • Report: Building AI-Era Network Fabrics

  • Quantum Safe Networks Market Pulse Report

Webinars

  • Appledore Webinar: Closing the Agent-Ready Data Gap for Autonomous Networks

  • Mimosa Webinar – Build the Right Network

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

Private 5G docks in Hamburg – as Deutsche Telekom and Ericsson scratch a...
India weighs rip-and-replace of legacy Chinese telecoms equipment
SK Telecom’s Topdda turns work vans into an AI inspection fleet

Latest Articles

Private 5G docks in Hamburg – as Deutsche Telekom and Ericsson scratch a seven-year itch
India weighs rip-and-replace of legacy Chinese telecoms equipment
SK Telecom’s Topdda turns work vans into an AI inspection fleet
Ciena sees AI driving multi-year optical infrastructure investment cycle

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign