This month's update includes two features - one that we have had enhanced in beta for a few months now, called MATRIX, and one that is new to our platform called Snapshot Sharing.
MATRIX
If you've been playing with this feature, you may have seen it referred to in our application as MAST (Beta). Today, we're formally rolling out our name for this feature, MATRIX, which stands for Mobile Application Testing and Reporting Interface.
MATRIX now includes 8 new Android checks and 4 new iOS checks.
New Android Checks
Category | Name |
---|
Auth | Application Contains Hardcoded URLs |
Crypto | Application Utilizing Insecure Cryptography |
Crypto | Application Utilizing Insecure Symmetric Encryption Modes |
Crypto | Application Contains Hardcoded SQLCipher Key |
Crypto | Application Contains Hardcoded API Keys |
Platform | Application Contains Debuggable Webviews |
Platform | Application Utilizes Insecure JavaScript Interface |
Platform | Application Contains WebViews with JavaScript Enabled |
Storage | Local Data Exposure: Sensitive Values Stored Insecurely in Memory |
New iOS Checks
Category | Name |
---|
Network | App Transport Security (ATS) Selectively Disabled |
Platform | Application Utilizes Potentially Dangerous Permissions |
Platform | Potentially Insecure iOS Entitlements |
Storage | Local Data Exposure: Sensitive Values Stored in Memory |
UI/UX Enhancements
Users are provided with guidance that offers a step-by-step process for completing a test. We have also included toast notifications to notify users when actions and tests have been completed. Once the tests have finished and you are ready to view the results, you can either view them in the UI or download the results in HTML or JSON formats.
The MATRIX index page has been redesigned to give users better access to their test results.
A summary has been added so you do not have to navigate to see your check results. Users can also sort by Status or Severity to easily find specific tests. Each test can expand to display the full list of all checks and results, including Impact, Remediation, and Evidence.
You will also see any tests that have not been completed, ensuring users always know where they left off. If a user tries to start a new test, they will be prompted to complete or delete the unfinished test.
A History section has been added, enabling users to view or delete old tests.
We believe readily available support documentation is crucial for quickly answering your questions, allowing you to stay focused on your tasks.
From the main MATRIX page, users can click out to view the MATRIX support homepage or the CI/CD workflow page.
Learn how to get started with MATRIX.
Bug fixes
We have continued to fix the bugs found during our Beta. Thank you to all of our select Business customers who have sent us comments about what they have experienced. We are proud to say that we have pushed all the fixes to those bugs into this release.
Known Issues
Rooted / Jailbroken
- MATRIX does not support non-rooted or non-jailbroken devices. To use MATRIX, ensure that the device is rooted (Android userdebug) or Jailbroken (iOS).
Project Admins Only
- Non-project admins who attempt to use MATRIX will be automatically logged out. This will change in future updates.
Keep the App Open
- When running MATRIX, ensure that the app is open in the virtual device until the report is generated. If the app is closed, there is a chance that the report will not be generated.
Snapshot Sharing
We are very excited about the new feature included in this release. Snapshot sharing allows users to distribute snapshots with other users within the platform. At this time, snapshot sharing is only available for Business customers only.
Learn how to get started with Snapshot sharing.
Snapshot sharing is controlled by Access Codes to ensure that only authorized individuals can use or share the snapshots, enhancing security and confidentiality.
Please note that when you create a new device from a shared live snapshot, the device's file system is copied to the new device, but the RAM state is not. This means the new device will boot up as if it were power-cycled but with the snapshot's file system state.
Virtualize iOS 17.5 Devices
Official iOS 17.5 support is now available for all customers who can virtualize compatible devices.