1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/detect-eavesdropping-in-your-mobile-app-with-trustkit/
7/11/2018 10:07:03 AM
Detect eavesdropping in your mobile app with TrustKit
Mobile Security,Spyware,Data Privacy
/Detect-Eavesdropping-in-Your-Mobile-App-With-TrustKit-App-Developer-Magazine_m1d845z8.jpg
App Developer Magazine

Security

Detect eavesdropping in your mobile app with TrustKit


Wednesday, July 11, 2018

Austin Harris Austin Harris

Detect and prevent eavesdropping with TrustKit Analytics mobile application security tool developed by Data Theorem.

Data Theorem, Inc. announced the availability of TrustKit Analytics, a new service for the TrustKit community that delivers advanced security insights. In addition, the company announced that since TrustKit’s release in 2015, it has identified more than 100 million eavesdropping attempts on iOS and Android applications, where apps in active mode have blocked 100 percent of those attempts. TrustKit is furthering anti-eavesdropping as a new standard in mobile application security.

Leveraging SSL Pinning, TrustKit enables mobile apps to provide comprehensive protection for the transmission of data. While SSL pinning has existed as a concept, their free open-source software development kit (SDK) is increasing the ease of equipping mobile applications with SSL pinning, enabling them to encrypt all communications, actively stop eavesdropping and block SSL man-in-the-middle (MiTM) attacks. This helps ensure user privacy, maintain data integrity, stop unauthorized spyware, and block unknown attackers from stealing user identity.

“TrustKit’s rapid growth and adoption represent an inflection point for mobile application security that benefits the privacy of user communication,” said Alban Diquet, Data Theorem Head of Engineering and author of TrustKit. “We owe it to our community for their adoption and work with us, which has allowed our new analytics service to deliver unique security insights to help customers understand how their applications are being violated from a privacy standpoint. Through this effort with our community, customers can develop mobile applications to be more secure with mobile than their web browser equivalent applications.”

TrustKit Analytics is a new and free service for their SDK users, delivering global visualization (geotagging) of the locations with the most eavesdropping attempts. The analytics service shows what percentage of eavesdropping attempts were actively blocked versus passively monitored, and whether the attempts came from end user device spyware, insecure public Wi-Fi, or corporate employer network monitoring. TrustKit Analytics also provides an easy path for customers to avoid irreversible downtime by setting up alerts to prevent malicious domain forging of SSL certificates and early detection of pinning misconfigurations. These alerts help customers avoid embarrassing mistakes and the loss of business due to avoidable downtime.

SSL pinning is a security capability that developers can leverage to prevent eavesdropping (MiTM) from occurring on data that transfers to and from their mobile apps by ensuring the client checks the server-side certificate against a known copy of that certificate. While the concept is well known, it has traditionally been difficult and time-consuming to implement, since it requires both significant operational and code-level changes. TrustKit facilitates code-level implementation to a "matter of minutes" by providing “drag and drop” SSL public key pinning. Whenever an eavesdropping attempt occurs, the TrustKit SDK within the application sends a notification report back to Data Theorem for the delivery of rich analytics, visualizations, and alerts of malicious attacks and potential downtime.

Detect eavesdropping in your mobile app with TrustKit







Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Featured Stories


Take It Down Act results in warning letters from FTC
Take It Down Act results in warning letters from FTC Friday, June 12, 2026


Nvidia valuation fears grow
Nvidia valuation fears grow Friday, June 12, 2026




Anthropic launches Claude Design
Anthropic launches Claude Design Wednesday, June 10, 2026


Spotlite Expands Into AI Era With New IP Protection Tool
Spotlite Expands Into AI Era With New IP Protection Tool Wednesday, June 3, 2026


Spotify and UMG strike landmark AI music licensing deal
Spotify and UMG strike landmark AI music licensing deal Thursday, May 28, 2026


Anthropic investigation opened after Mythos accessed by Discord group
Anthropic investigation opened after Mythos accessed by Discord group Wednesday, May 27, 2026


AI layoffS: What is really behind it all
AI layoffS: What is really behind it all Tuesday, May 26, 2026


The identity system is failing under AI
The identity system is failing under AI Monday, May 25, 2026


The Real World Launches Expert-Verified AI Certification Framework
The Real World Launches Expert-Verified AI Certification Framework Friday, May 22, 2026


Multiple language options when developing apps with Evoke
Multiple language options when developing apps with Evoke Thursday, May 21, 2026


Get More App News



/sites/themes/prod/assets/js/less.js"> ' %>