Tracing Cryptographic Agility in Android and iOS Apps

Kris Heid, Jens Heider, Matthias Ritscher, Jan-Peter Stotz

2023

Abstract

Cryptography algorithms are applicable in many use cases such as for example encryption, hashing, signing. Cryptography has been used since centuries, however some cryptography algorithms have been proven to be easily breakable (under certain configurations or conditions) and should thus be avoided. It is not easy for a developer with little cryptographic background to choose secure algorithms and configurations from the plenitude of options. Several publications already proved the disastrous cryptographic quality in mobile apps in the past. In this publication we research how cryptography of the top 2000 Android and iOS applications evolved over the past three years. We analyze at the example of the weak AES/ECB mode how and why apps changed from an insecure to a secure configuration and vice versa.

Download


Paper Citation


in Harvard Style

Heid K., Heider J., Ritscher M. and Stotz J. (2023). Tracing Cryptographic Agility in Android and iOS Apps. In Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-624-8, pages 38-45. DOI: 10.5220/0011620000003405


in Bibtex Style

@conference{icissp23,
author={Kris Heid and Jens Heider and Matthias Ritscher and Jan-Peter Stotz},
title={Tracing Cryptographic Agility in Android and iOS Apps},
booktitle={Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2023},
pages={38-45},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011620000003405},
isbn={978-989-758-624-8},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 9th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Tracing Cryptographic Agility in Android and iOS Apps
SN - 978-989-758-624-8
AU - Heid K.
AU - Heider J.
AU - Ritscher M.
AU - Stotz J.
PY - 2023
SP - 38
EP - 45
DO - 10.5220/0011620000003405