OWASP ‘Top 10 Mobile Risks’ – Part 1

OWASP (Open Web Application Security Project) has come up with a top 10 risks for the mobile technology. This list is in the ‘beta’ stage. The list, released on 23rd September 2011, has been under a 60 day review period and is due for a final version release any time. When released, this will be the first official version of OWASP top 10 for mobile applications.  The current list of OWASP Top 10 Mobile Risks (Release candidate) is reproduced below:

  1. Insecure Data Storage
  2. Weak Server Side Controls
  3. Insufficient Transport Layer Protection
  4. Client Side Injection
  5. Poor Authorization and Authentication
  6. Improper Session Handling
  7. Security Decisions Via Untrusted Inputs
  8. Side Channel Data Leakage
  9. Broken Cryptography
  10. Sensitive Information Disclosure

The above list of risks are platform agnostic. Also the OWASP project team, working on the ‘Top 10’ have changed their approach from ‘Vulnerability’ centric list to ‘Risk’ centric list.  When OWASP releases the final version of this list, IT security fraternity will be seeing a clear mobile security roadmap emerge. In the next part, we shall look into what each of these risks mean. In the final part of this series of OWASP top 10, we shall look into the Top 10 mobile controls recommended by OWASP.