In this just released video from the Open Web App Security Project (OWASP) AppSecUSA 2011 conference held in Minneapolis, MN, Mike Park discusses the insecurity of Android “.apk” apps and covers the ease with which Android Apps can be reversed, the ability to store sensitive data locally, and how these apps can be trojaned to access personal information on the device. He also covers open source tools for reversing and the use of the Android SDK features for pen testing.
