View in English

  • Apple Developer
    • Get Started

    Explore Get Started

    • Overview
    • Learn
    • Apple Developer Program

    Stay Updated

    • Latest News
    • Hello Developer
    • Platforms

    Explore Platforms

    • Apple Platforms
    • iOS
    • iPadOS
    • macOS
    • tvOS
    • visionOS
    • watchOS
    • App Store

    Featured

    • Design
    • Distribution
    • Games
    • Accessories
    • Web
    • Home
    • CarPlay
    • Technologies

    Explore Technologies

    • Overview
    • Xcode
    • Swift
    • SwiftUI

    Featured

    • Accessibility
    • App Intents
    • Apple Intelligence
    • Games
    • Machine Learning & AI
    • Security
    • Xcode Cloud
    • Community

    Explore Community

    • Overview
    • Meet with Apple events
    • Community-driven events
    • Developer Forums
    • Open Source

    Featured

    • WWDC
    • Swift Student Challenge
    • Developer Stories
    • App Store Awards
    • Apple Design Awards
    • Apple Developer Centers
    • Documentation

    Explore Documentation

    • Documentation Library
    • Technology Overviews
    • Sample Code
    • Human Interface Guidelines
    • Videos

    Release Notes

    • Featured Updates
    • iOS
    • iPadOS
    • macOS
    • watchOS
    • visionOS
    • tvOS
    • Xcode
    • Downloads

    Explore Downloads

    • All Downloads
    • Operating Systems
    • Applications
    • Design Resources

    Featured

    • Xcode
    • TestFlight
    • Fonts
    • SF Symbols
    • Icon Composer
    • Support

    Explore Support

    • Overview
    • Help Guides
    • Developer Forums
    • Feedback Assistant
    • Contact Us

    Featured

    • Account Help
    • App Review Guidelines
    • App Store Connect Help
    • Upcoming Requirements
    • Agreements and Guidelines
    • System Status
  • Quick Links

    • Events
    • News
    • Forums
    • Sample Code
    • Videos
 

Vídeos

Abrir menu Fechar menu
  • Coleções
  • Todos os vídeos
  • Sobre

Mais vídeos

  • Sobre
  • Código
  • Secure your app: threat modeling and anti-patterns

    It's more important than ever to consider vulnerabilities and potential threats and recognize where you should apply safeguards in your app. Understand how to identify potential risks through threat modeling and how to avoid common anti-patterns. Learn coding techniques and how to take advantage of platform-supplied protections to help you mitigate risk and protect people while they're using your app.

    Recursos

    • iOS Security White Paper
      • Vídeo HD
      • Vídeo SD

    Vídeos relacionados

    WWDC20

    • Build trust through better privacy
  • Buscar neste vídeo...
    • 16:34 - Path traversal

      func handleIncomingFile(_ incomingResourceURL: URL, with name: String, from fromID: String) {
          guard
               case let safeFileName = name.lastPathComponent, 
               safeFileName.count > 0,
               safeFileName != "..", safeFileName != "." else { return }
      
          let destinationFileURL = URL(fileURLWithPath: NSTemporaryDirectory())
                                       .appendingPathComponent(safeFileName)
      
          // Copy the file into a temporary directory
          try! FileManager.default.copyItem(at: incomingResourceURL, to: destinationFileURL)
      
      }
    • 22:26 - State management

      func handleSessionInviteAccepted(with message: RemoteMessage, from fromID: String) {
          guard session = sessionsByIdentifier[message.sessionIdentifier],
                session.state == .inviting,
                session.invitedFromIdentifiers.contains(fromID) else { return }
      
          session.state = .connected
          session.setupSocket(to: fromID) { socket in
              cameraController.send(to: socket)
          }
      }
    • 30:56 - Safe dynamic allowedClasses

      NSSet *classesWhichConformToProtocol(Protocol *protocol) {
          NSMutableSet *conformingClasses = [NSMutableSet set];
          
          unsigned int classesCount = 0;
          Class *classes = objc_copyClassList(&classesCount);
          if (classes != NULL) {
              for (unsigned int i = 0; i < classesCount; i++) {
                  if (class_conformsToProtocol(classes[i], protocol)) {
                      [conformingClasses addObject: classes[i]];
                  }
              }
              free(classes);
          }
          return conformingClasses;
      }
    • 34:23 - Buffer overflows

      @implementation
      - (BOOL)unpackTeaClubRecord:(CKRecord *)record {
          ...
          NSData *data = [record objectForKey:@"uuid"];
          if (data == nil ||
              ![data isKindOfClass:[NSData class]] ||
              data.length != sizeof(_uuid)) {
              return NO;
          }
          memcpy(&_uuid, data.bytes, data.length);
          ...
    • 36:06 - Integer overflows

      @implementation
      - (BOOL)unpackTeaClubRecord:(CKRecord *)record {
          ...
          NSData *name = [record objectForKey:@"name"];
          int32_t count = [[record objectForKey:@"nameCount"] unsignedIntegerValue];
          int32_t byteCount = 0;
          if (name == nil ||
              ![name isKindOfClass:[NSData class]] ||
              os_mul_overflow(count, sizeof(unichar), &byteCount) ||
              name.length != byteCount) {
              return NO;
          }
          _name = [[NSString alloc] initWithCharacters:name.bytes 
                                                length:count];
          ...

Developer Footer

  • Vídeos
  • WWDC20
  • Secure your app: threat modeling and anti-patterns
  • Open Menu Close Menu
    • iOS
    • iPadOS
    • macOS
    • tvOS
    • visionOS
    • watchOS
    • App Store
    Open Menu Close Menu
    • Swift
    • SwiftUI
    • Swift Playground
    • TestFlight
    • Xcode
    • Xcode Cloud
    • Icon Composer
    • SF Symbols
    Open Menu Close Menu
    • Accessibility
    • Accessories
    • Apple Intelligence
    • Audio & Video
    • Augmented Reality
    • Business
    • Design
    • Distribution
    • Education
    • Games
    • Health & Fitness
    • In-App Purchase
    • Localization
    • Maps & Location
    • Machine Learning & AI
    • Security
    • Safari & Web
    Open Menu Close Menu
    • Documentation
    • Downloads
    • Sample Code
    • Videos
    Open Menu Close Menu
    • Help Guides & Articles
    • Contact Us
    • Forums
    • Feedback & Bug Reporting
    • System Status
    Open Menu Close Menu
    • Apple Developer
    • App Store Connect
    • Certificates, IDs, & Profiles
    • Feedback Assistant
    Open Menu Close Menu
    • Apple Developer Program
    • Apple Developer Enterprise Program
    • App Store Small Business Program
    • MFi Program
    • Mini Apps Partner Program
    • News Partner Program
    • Video Partner Program
    • Security Bounty Program
    • Security Research Device Program
    Open Menu Close Menu
    • Meet with Apple
    • Apple Developer Centers
    • App Store Awards
    • Apple Design Awards
    • Apple Developer Academies
    • WWDC
    Read the latest news.
    Get the Apple Developer app.
    Copyright © 2026 Apple Inc. All rights reserved.
    Terms of Use Privacy Policy Agreements and Guidelines