Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Writing Secure Code in iOS by Infosec

Writing Secure Code in iOS by Infosec

16h 6mIntermediate2025-08-06

Authors

Infosec Institute

Infosec Institute

Course details

Learn how to incorporate security in iOS application development for mobile devices. Focusing mostly on Swift, Apple's programming language, you’ll explore the best practices for addressing some of the most common iOS security mistakes and the limits of Swift as a secure language. Each section of the course covers a major iOS security category, including examples that give you a hands-on idea of the impact of missing or poor security in a code snippet. You’ll also get a chance to apply everything you’ve learned by testing an app and ensuring that security risks have been mitigated. An ideal fit for security professionals and beginning- and intermediate-level app developers and programmers, this course equips with the skills you need to develop a successful iOS app using Swift.

Learning objectives
Integrate secure coding practices in your iOS application development.
Validate input using Swift.
Limit the risk of overflows in Swift.
Encrypt data in iOS using Swift.
Use Swift to protect data at rest and data in transit.
Implement access control in iOS apps.
Maintain the integrity of your iOS app and device.

Skills covered

iOS SDKXcodeSoftware Development SecurityiOS DevelopmentMobile DevelopmentAppleCybersecurityOne-Off

Concepts

0. Introduction

  • 01 - Welcome to secure coding in iOS

1. Introduction to Secure Coding

  • 02 - The need for secure coding
  • 03 - Activity - OWASP top 10 mobile vulnerabilities, part 1
  • 04 - Activity - OWASP top 10 mobile vulnerabilities, part 2
  • 05 - Activity - OWASP top 10 mobile vulnerabilities, part 3
  • 06 - iOS security overview, part 1
  • 07 - iOS security overview, part 2
  • 08 - Swift secure app development overview, part 1
  • 09 - Swift secure app development overview, part 2
  • 10 - iOS general development best practices

2. Input Validation

  • 11 - Understanding input risks
  • 12 - Autocorrect and autofill
  • 13 - Activity - Disabling autocorrection
  • 14 - Special characters, part 1
  • 15 - Special characters, part 2
  • 16 - Format string attack, part 1
  • 17 - Format string attack, part 2
  • 18 - Format string attack, part 3
  • 19 - Activity - Playing with format strings
  • 20 - Input sanitization
  • 21 - Input sanitization techniques - Regular expressions, part 1
  • 22 - Input sanitization techniques - Regular expressions, part 2
  • 23 - Activity - Regular expressions, part 1
  • 24 - Activity - Regular expressions, part 2
  • 25 - Activity - Regular expressions, part 3
  • 26 - Activity - Sanitizing input, part 1
  • 27 - Activity - Sanitizing input, part 2
  • 28 - Property wrappers
  • 29 - Activity - Trimming whitespace and newlines with a property wrapper
  • 30 - Activity - Value clamping with a property wrapper
  • 31 - Activity - Sanitizing input with a property wrapper
  • 32 - Null bytes
  • 33 - Cross-site attacks
  • 34 - Activity - Exploring XSS attacks
  • 35 - Code injection
  • 36 - Activity - Filtering a malicious QR code, part 1
  • 37 - Activity - Filtering a malicious QR code, part 2
  • 38 - SQL injection, part 1
  • 39 - SQL injection, part 2
  • 40 - Object deserialization
  • 41 - Activity - Installing Alamofire and SwiftyJSON pods
  • 42 - Activity - Securely working with JSON, part 1
  • 43 - Activity - Securely working with JSON, part 2
  • 44 - WebView protection
  • 45 - Activity - Protecting users against insecure UIWebView

3. Memory Corruption

  • 46 - iOS memory overview
  • 47 - Swift pointers
  • 48 - Understanding overflows
  • 49 - Activity - Creating a buffer overflow

4. Encryption

  • 50 - iOS storage overview
  • 51 - Activity - Exploring the iOS file system
  • 52 - Activity - Preparing for encryption
  • 53 - Core Data
  • 54 - Data persistence, part 1
  • 55 - Data persistence, part 2
  • 56 - Activity - Saving a username and password
  • 57 - Activity - Verifying a username and password, part 1
  • 58 - Activity - Verifying a username and password, part 2
  • 59 - Encryption overview, part 1
  • 60 - Encryption overview, part 2
  • 61 - Keychain
  • 62 - Activity - Preparing to use Keychain
  • 63 - Activity - Save user secrets in Keychain
  • 64 - Hashing
  • 65 - Activity - Generating random values
  • 66 - Activity - Hashing passwords
  • 67 - Activity - Adding salt to a password hash

5. Protecting Data

  • 68 - Common data risks, part 1
  • 69 - Common data risks, part 2
  • 70 - Protecting files, part 1
  • 71 - Protecting files, part 2
  • 72 - Activity - Saving data in a Realm database
  • 73 - Network security
  • 74 - Activity - Making an HTTP exception
  • 75 - App backgrounding
  • 76 - Activity - Securely backgrounding an app
  • 77 - API security
  • 78 - Activity - Storing an API key in Keychain
  • 79 - Interprocess communications (IPC), part 1
  • 80 - Interprocess communications (IPC), part 2
  • 81 - Activity - Preventing race conditions

6. Access Control

  • 82 - Apple ID
  • 83 - Activity - Sign in with Apple ID
  • 84 - Biometrics
  • 85 - Activity - Logging in with biometrics
  • 86 - Authorization
  • 87 - Activity - Role-based access control
  • 88 - One-time passwords
  • 89 - Activity - Using a one-time password

7. Protecting Software and System Integrity

  • 90 - Understanding risks associated with external code
  • 91 - Activity - Working with external code
  • 92 - Error handling
  • 93 - Activity - Handling errors
  • 94 - Logging, part 1
  • 95 - Logging, part 2
  • 96 - Logging, part 3
  • 97 - Testing types
  • 98 - Jailbreak detection
  • 99 - Activity - Detecting a jailbroken device
  • 100 - New vulnerability research
  • 101 - Secure iOS coding roundup

Conclusion

  • 102 - Conclusion

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal