# Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390 Page: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Text version: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390.md Podcast: [Security Weekly Podcast Network (Audio)](https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755) Published: 2026-07-07T09:00:00+00:00 Episode link: http://sites.libsyn.com/18678/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/pauldotcom/ASW_390_1--4b0e21d2-3c69-44d3-be69-a71716049e47--audio-converted--588e1185-e8ad-46c1-8e0a-daee242b1d64.mp3?dest-id=13427 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Duration seconds: 2873 ## Resource Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust. Segment Resources: https://hubs.la/Q04jLKj70 https://mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering/ https://owasp.org/API-Security/editions/2023/en/0x00-header/ This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-390 ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.