>_ FIELD_NOTES
[LOG.OPEN] ROLAND SANOU — WHAT BROKE, WHY, AND WHAT REPLACED IT.
WRITTEN WHILE THE DETAIL WAS STILL FRESH.
Auditing a banking Android app without lying to yourself
Four axes, and above all the traps that make a static APK audit report "compliant" when it checked nothing. Method applied to banking and mobile-money apps in the West African UEMOA zone.
99% accurate, and detecting nothing
A malware classifier can score beautifully in validation and collapse in production. Three corpus biases account for almost every case — and none of them is visible in a confusion matrix.
Mapping an organisation's exposure without touching it
Building the external attack surface of a bank or a telecom operator from public sources — and the four bugs that turn that map into fiction, including one that credits a stranger's leaked secrets to your client.
The bug that emptied every Android manifest
A sixteen-byte offset error in Android's binary XML format returned zero attributes from every conformant app. No exception, no warning — just an audit calling things clean that it had never read.