ITSPmagazine

From Fraud to Fixes: Designing Usable Security for Financial Applications | An OWASP AppSec Global 2025 Conversation with Wojciech Dworakowski | On Location Coverage with Sean Martin and Marco Ciappelli

Jun 2, 2025
Wojciech Dworakowski, OWASP Poland Board Member and Managing Partner at SecuRing, dives into the vulnerabilities of mobile banking apps, highlighting their risks due to reliance on smartphones for transaction authorization. He shares insights on how attack strategies have evolved from simply stealing cards to sophisticated account takeovers. Wojciech advocates for a multi-layered security approach, emphasizing enhanced device fingerprinting and shared interbank databases as solutions to bolster security without sacrificing user experience.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Mobile Banking's Single Point Risk

  • Modern mobile banking apps converge transaction initiation, authorization, and security settings on one smartphone device.
  • This concentration creates a single failure point whereby an attacker controlling the device gains full account access.
ANECDOTE

Personal Loss Highlights Attack Threat

  • Wojciech shares a personal story about his daughter being socially engineered and losing all her e-commerce money.
  • This highlights the real-world impact of account takeover attacks beyond theoretical risks.
ADVICE

Raise the Bar Security Strategy

  • Implement multiple defensive steps to 'raise the bar' against attackers rather than relying on a single security solution.
  • Use device fingerprinting, emulator and rooting detection, and shared interbank device reputation databases.
Get the Snipd Podcast app to discover more snips from this episode
Get the app