Matomo

Product security for one of the biggest African banks | Cossack Labs
Case studies
Product security for one of the biggest African banks

Product security for one of the biggest African banks

APR - JUL 2023 Banking Mobile Security assurance
Product security for one of the biggest African banks

Overview

Industry

  • Banking
  • Financial Service Authority

Technology stack

  • iOS Swift
  • Android Kotlin
  • Windows-based backend

Regulations

  • Typical fintech security requirements, PCI DSS
  • Data privacy regulations
  • Encryption export regulations

Challenges

[01]

KYC for enhanced authentication

KYC (Know Your Customer) is an effective method of validating the user's identity by requesting a selfie video from the user's phone. A user should upload their documents to create an account, and then the system matches the video to the documents to complete the app setup. Making this feature user-friendly is the primary challenge to avoid poor user experience.

[02]

Device binding

A particular smartphone is linked to a specific user account. When users log into the app from a different phone, they must repeat the KYC validation process. This requirement is hard to get right, but it is essential for mobile app's security posture.

[03]

Data privacy and fintech regulations

We analysed the requirements from data privacy regulations of African countries' (including NDPR and Lagos data privacy bill), financial and banking regulations (PCI DSS, rapid payment standards) to recommend appropriate security measures to ensure that users’ activities do not cause financial damage to the bank.

[04]

Balanced UX and security of authentication

The app implements multiple authentication factors but it skips particular authentication steps to improve UX if the device and the user are already known to the system. The challenge is to ensure that an unauthorised user cannot bypass the checks.

Technology requirements

Technology requirements

Support old phones

85% of bank clients use Android phones, many of which are old devices with significantly outdated operating systems, heightening security risk. The outdated OS does not have newest security patches which increases the attack surface and makes devices easier to exploit. The new banking app should work on older phones yet provide adequate security guarantees.

Consistent security for iOS and Android

New mobile applications are native, built in Swift and Kotlin, and have an independent code base. Security controls should be consistent across apps while being tailored to each operating system's weaknesses and strengths.

Device trust

Device binding works well only on trusted devices. Device trust controls include protection against reverse engineering, detection of rooted/jailbroken smartphones and specific OS exploits, and confirmation that the app is installed from the official AppStore / Google Play.

Anti-fraud and anti-abuse system

Great popularity among users attracts a massive amount of financial fraud. The fraud prevention team at the bank has shared details about previously seen fraud cases. We have suggested many recommendations to improve the anti-fraud system based on the user behaviour inside the app.

Our approach

Mobile-specific expertise

Our expertise in security engineering, coupled with understanding of the challenges of different mobile phones and mobile OSs, enabled us to find effective solutions, tailored to the specific risks and requirements.

Data lifecycle focus

We treat mobile apps as a gateway to a larger system. Our expertise extends to designing secure APIs, authentication mechanisms, reverse-engineer protections, mobile-specific controls to ensure the protection of all user assets throughout the data lifecycle.

Proactive security measures

While it is tempting to focus on reactive controls, a bank cannot afford to limit themselves with chasing thieves. Taking preventive measures, combining them with detective and reactive controls, proved to be effective in mitigating risks and vulnerabilities.

Engineer-to-engineer collaboration

Regular collaboration with security engineers is essential to get the optimal security impact. It is ineffective to just point out what is wrong. We usually make certain that whatever is necessary (explanations, workshops, code), gets done to reach a shared understanding of security posture and its problems.
Our approach

Solution

Initial risk assessment and rapid threat modelling

A fragment of data classification for assets appeared on the mobile application.
A fragment of data classification for assets appeared on the mobile application.

Mobile security validation, CL MSS

Mobile application security and platform trust assessment

crucial and high issues

API security

Protecting the application itself

Anti fraud system

Future product security work

The status of banking applications after security assessment and one month of issues fixing by the development team.
The status of banking applications after security assessment and one month of issues fixing by the development team.

Results and outcomes

Having successfully passed the Beta testing stage, the bank released their new app to the public. It is still too early to tell how effective the new fraud detection system is, but there has not been a significant increase in fraud so far.

Our security engineers walked the backend and mobile teams of the bank step by step, answering their questions and searching for optimal solutions. We recommended security controls that met the needs of both the product and security teams, while still being user-friendly.

The security posture of the bank application has improved significantly after months of hard work. After fixing the discovered issues, the security score increased by a factor of two, covering all basic security requirements and implementing some of the advanced ones. We worked with the bank team, aiming for “root cause” decisions on security weaknesses. After a vast portion of phone calls, design sessions, discussions with product, engineering and anti-fraud bank teams, we managed to find optimal solutions to the existing problems.

We are experts in proactive product security. We filled the backlog of both the mobile and backend teams with security improvements for months ahead. This will ensure that security remains a priority even after our cooperation ends.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days