EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead

Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security best practices, and doesn’t take advantage of the latest tools made available by Google to mitigate the risk of locally-stored sensitive data. This post explores what those tools are, discusses previous (now deprecated) methods for securing data locally, and provides recommendations for what Android developers should do if storing sensitive data is unavoidable.

Web App Pentesting in the AI Era

The IncludeSec team explores the practical considerations of AI-assisted source code analysis. Observing results produced with frontier vs locally-hosted models, various harness orchestration designs, and a list of different language frameworks provided us with meaningful insights into how the modern pentester should be using AI to produce higher quality results (but not necessarily in less time!)

The AWS Console and Terraform Security Gap

Are you using Terraform to build or configure your AWS environment? You might be surprised by configuration settings that introduce vulnerabilities by default, particularly if you’re already familiar with using the AWS or other cloud provider interfaces for asset creation. This post focuses on the slowly growing security divide of AWS asset security settings when created by the Terraform provider vs the AWS UI.

Production Security, Not That Kind

The Include Security team takes a foray into the world of audio production equipment in our latest blog post. We look under the hood of a professional-grade audio mixer to explore its security profile, consider how its functionality could be leveraged by an attacker in a real world setting, and develop a proof-of-concept exploit to demonstrate quick n’ easy privilege escalation.