# Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390 Page: https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Text version: https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390.md Podcast: [Security Weekly Podcast Network (Video)](https://stenobird.com/podcast/security-weekly-podcast-network-video-841420) Published: 2026-07-07T09:00:00+00:00 Episode link: https://securityweeklytv.libsyn.com/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/securityweeklytv/ASW_390_1--4b0e21d2-3c69-44d3-be69-a71716049e47--sd-converted--ff4cfe43-bef1-4333-b853-3f9ee319b05f.mp4?dest-id=292819 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-video-841420/episodes/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390 Duration seconds: 2873 ## Resource Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust. Segment Resources: https://hubs.la/Q04jLKj70 https://mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering/ https://owasp.org/API-Security/editions/2023/en/0x00-header/ This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Show Notes: https://securityweekly.com/asw-390 ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-video-841420/episodes/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/defense-in-depth-strategies-for-securing-mobile-applications-ryan-lloyd-asw-390.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.