Mobile Security Theater – or why YOU should pay $1,000,000 for two regex queries
-
Miłosz Gaczkowski - BSidesLjubljana 0x7E8
Miłosz Gaczkowski No video found
In this talk, I will share my experiences of testing and reverse-engineering some of the big names’ MDMs and anciliary security applications (without naming any of them), focusing on some of our most bizarre findings. Some notable examples will feature:
The aim of this lighthearted talk is to highlight the overpromising and underdelivering which is prevalent in the mobile security market, and to point out that many of the problems these solutions promise to address have already been tackled by device manufacturers.
The talk will be aimed at a fairly general audience, hoping to sit well with both technical and managerial security folks. Rather than showing snippets of code, I will focus on high-level descriptions of security features that don’t actually do anything useful. I will not be able to name specific vendors, but most of them are guilty of at least one of the sins I hope to highlight :)