Methodology: iOS Authentication Testing
See also: workflows/auth_testing.md for the runbook.
Axes of Review
- Local gate — PIN, pattern, biometric. Can Frida flip the result? If yes, does it actually grant access to protected data or just UI?
- Server gate — Does the server independently validate each sensitive request? Or does it trust a "logged in" flag?
- Session management — Token lifetime, rotation on password change, logout invalidates server-side, device binding.
- Credential storage — Keychain with appropriate accessibility +
SecAccessControl?
Biometric Hook Points
-[LAContext canEvaluatePolicy:error:]-[LAContext evaluatePolicy:localizedReason:reply:]-[LAContext evaluateAccessControl:operation:localizedReason:reply:]ReturnYES/ invoke reply with success = bypass unless Keychain gate also requires actual biometric for item retrieval (then the key won't decrypt and app fails downstream — positive signal of strong design).
OAuth / SSO
- Capture auth redirect flow in Burp.
- Check PKCE (
code_challenge,code_challenge_method=S256). - Check redirect URI allowlist (app-scheme:// URI).
- Attempt scheme hijack: install a sibling app claiming the same scheme.
WebView Auth
WKWebViewauth forms: inspectevaluateJavaScript:usage, cookie sharing.SFSafariViewControlleris more isolated; flag use ofWKWebViewfor SSO as weaker.
Rate Limiting / Lockout
Server-side — out of MASTG client scope, but note behaviour when 20 wrong PINs are attempted locally (app-level lockout) and whether a reinstall resets the counter.