Mobile Application Assessment with Chris Crowley, SANS Institute – Paul’s Security Weekly #529

Chris Crowley is a SANS instructor and independent consultant based in the Washington, D.C. area. Mr. Crowley overviews his approach to keeping mobile applications secure in this technical segment! Full Show Notes Subscribe to YouTube Channel

The post Mobile Application Assessment with Chris Crowley, SANS Institute – Paul’s Security Weekly #529 appeared first on Security Weekly.

Continue reading Mobile Application Assessment with Chris Crowley, SANS Institute – Paul’s Security Weekly #529

A Hardware Privacy Monitor for iPhones

Andrew "bunnie" Huang and Edward Snowden have designed a hardware device that attaches to an iPhone and monitors it for malicious surveillance activities, even in instances where the phone’s operating system has been compromised. They call it an Introspection Engine, and their use model is a journalist who is concerned about government surveillance: Our introspection engine is designed with the… Continue reading A Hardware Privacy Monitor for iPhones

Hacking a Phone Through a Replacement Touchscreen

Researchers demonstrated a really clever hack: they hid malware in a replacement smart phone screen. The idea is that you would naively bring your smart phone in for repair, and the repair shop would install this malicious screen without your knowledge. The malware is hidden in touchscreen controller software, which is trusted by the phone. The concern arises from research… Continue reading Hacking a Phone Through a Replacement Touchscreen

Criminals are Now Exploiting SS7 Flaws to Hack Smartphone Two-Factor Authentication Systems

I’ve previously written about the serious vulnerabilities in the SS7 phone routing system. Basically, the system doesn’t authenticate messages. Now, criminals are using it to hack smartphone-based two-factor authentication systems: In short, the issue with SS7 is that the network believes whatever you tell it. SS7 is especially used for data-roaming: when a phone user goes outside their own provider’s… Continue reading Criminals are Now Exploiting SS7 Flaws to Hack Smartphone Two-Factor Authentication Systems

Stealing Browsing History Using Your Phone’s Ambient Light Sensor

There has been a flurry of research into using the various sensors on your phone to steal data in surprising ways. Here’s another: using the phone’s ambient light sensor to detect what’s on the screen. It’s a proof of concept, but the paper’s general conclusions are correct: There is a lesson here that designing specifications and systems from a privacy… Continue reading Stealing Browsing History Using Your Phone’s Ambient Light Sensor