Software Engineering Daily · softwareengineeringdaily.com

Mobile App Security with Ryan Lloyd09

April 9, 2026·55 min·4 clips
Attackers reverse-engineer your bank's official app, inject malware, then trick you into installing the fake update.
Mobile apps now carry serious workflows. The cold open uses banking, payments, and healthcare to frame the basic problem: important logic and intellectual property sit on a user's device, outside the developer's control. Ryan Lloyd keeps returning to that asymmetry as he explains reverse engineering, runtime manipulation, fraud, and why mobile security does not map neatly onto web or desktop habits. GuardSquare gives the discussion something concrete to work with. Its platform comes up through layered code obfuscation, runtime application self-protection, mobile-specific testing, threat monitoring, and API attestation. The best section is the obfuscation stretch. Lloyd explains that attackers are looking for useful knowledge inside decompiled code, so the goal is to make that code painful enough to understand that the effort stops looking worth it. The host makes a helpful comparison to minification, then draws the line between ordinary compression-like obscurity and protection meant to resist simple reversal. Name changes are only the starting point. Lloyd describes class names, method names, and application objects being swapped for short, plain identifiers while the useful mapping file stays inside the organization. That mapping file is the difference between controlled confusion and total self-sabotage. Without it, an outsider has a much harder time rebuilding the app into readable structure after decompilation. Then the layers get heavier: encrypted classes, hidden encryption logic, string encryption, and control-flow obfuscation. The tone stays grounded. Nobody claims reversal becomes impossible. The stronger claim is that good protection raises complexity and time cost. Runtime defense widens the picture, with self-protection, testing, monitoring, and attestation treated as parts of the same mobile posture. LLMs show up as another attacker tool, not a reason to throw away established hardening work.

As heard by us

A practical, developer-facing look at why mobile apps need defenses beyond ordinary web security habits.

Mobile app security gets framed here as a control problem: important code and business logic often live on a user's device, where developers cannot fully govern the environment.

Read the full review in PlayNext →

Why you'd press play

Your app's business logic ships to every user's phone, and some of those users have decompilers.

Read the full recommendation in PlayNext →
Listen to the show on