1 00:00:02,009 --> 00:00:05,340 Mishaal: Hello, and welcome to Android bys powered by Esper, the podcast that 2 00:00:05,340 --> 00:00:07,200 dives deep into the world of Android. 3 00:00:07,500 --> 00:00:08,520 I'm Michelle Ramon. 4 00:00:08,520 --> 00:00:11,760 And while I'd normally be joined by my co-host David Ruddock, he unfortunately 5 00:00:11,765 --> 00:00:13,080 couldn't make it to this one. 6 00:00:13,350 --> 00:00:13,740 Still. 7 00:00:13,740 --> 00:00:16,770 We've got a great topic and guest lined up on the show this week, 8 00:00:16,770 --> 00:00:19,740 we'll be talking about security, specifically mobile app security. 9 00:00:19,920 --> 00:00:23,100 So if you listen to our podcast before, you know, we've talked about Android 10 00:00:23,100 --> 00:00:26,220 security model, at least when it comes to applications, as well as our 11 00:00:26,220 --> 00:00:27,840 permissions work in the previous episode. 12 00:00:28,205 --> 00:00:31,415 But this time, we want to focus more specifically on how Google app 13 00:00:31,415 --> 00:00:35,705 developers and outside firms team up to protect you and your Android device. 14 00:00:35,915 --> 00:00:40,144 So today we've invited Brian Reed, chief mobility officer at now secure 15 00:00:40,175 --> 00:00:41,495 to talk about mobile app security. 16 00:00:41,500 --> 00:00:42,455 Welcome to the show, 17 00:00:42,460 --> 00:00:42,785 Brian: Brian. 18 00:00:43,410 --> 00:00:44,040 Thanks, Michelle. 19 00:00:44,040 --> 00:00:45,900 It's great to be here and part of your community. 20 00:00:45,900 --> 00:00:46,680 Thanks for having me. 21 00:00:46,890 --> 00:00:47,700 Thanks for joining us. 22 00:00:47,700 --> 00:00:48,030 So 23 00:00:48,360 --> 00:00:52,290 Mishaal: this is the topic that in my now seven years of covering Android, you know, 24 00:00:52,290 --> 00:00:57,000 I've kind of delved into the security side a bit here and there, even though, while 25 00:00:57,000 --> 00:01:00,930 it's been up in my primary focus, just covering the Android platform ecosystem, 26 00:01:00,930 --> 00:01:05,100 these security issues come up and tend to cover them pretty much every week. 27 00:01:05,100 --> 00:01:07,920 You'll hear from some mobile security threat firm that there's 28 00:01:07,920 --> 00:01:11,370 some new malware strain out in the wild, and that is wing havoc. 29 00:01:11,634 --> 00:01:15,145 And then when you dive into the details you discover, oh, they're mostly misusing 30 00:01:15,145 --> 00:01:19,315 some Android API or application some permission or they're tricking users 31 00:01:19,315 --> 00:01:21,475 into enabling some sensitive permiss. 32 00:01:22,304 --> 00:01:25,964 And so like, this is a topic that is ever pervasive in our lives, because 33 00:01:25,964 --> 00:01:31,125 you probably know people in your lives who could be tricked into enabling 34 00:01:31,125 --> 00:01:33,315 something they shouldn't have when songs something they shouldn't have. 35 00:01:33,884 --> 00:01:37,664 And even if you think that you wouldn't do that, there's a very high 36 00:01:37,664 --> 00:01:39,014 chance that you could be tricked to. 37 00:01:39,074 --> 00:01:44,475 No one is ever completely foolproof from fishing or any other malware attacks. 38 00:01:45,190 --> 00:01:47,440 There are many things you can do to prevent yourself from 39 00:01:47,440 --> 00:01:48,400 being taken advantage of. 40 00:01:48,730 --> 00:01:51,850 But on the ecosystem side, there are also many things that Android 41 00:01:51,850 --> 00:01:56,560 does and that Google does and that outside firms can do to proactively 42 00:01:56,560 --> 00:01:58,960 protect you from harming yourself. 43 00:01:59,290 --> 00:02:02,350 So just so we're all on the same page, I kind of wanna just touch upon 44 00:02:02,355 --> 00:02:06,790 the background of Android security model and how Android actually 45 00:02:06,790 --> 00:02:08,259 protects you at a platform level. 46 00:02:08,440 --> 00:02:10,960 So we talked about this before, but every time you install 47 00:02:10,960 --> 00:02:12,610 an app, it comes an APK file. 48 00:02:12,615 --> 00:02:13,870 And within that APK file. 49 00:02:14,095 --> 00:02:17,755 There's all the assets, the code, the resources, et cetera, but there's also 50 00:02:17,755 --> 00:02:21,535 a digital signature that is generated whenever the developer signs a package. 51 00:02:21,894 --> 00:02:25,855 And whenever that app installs on your device, it's given a unique package name. 52 00:02:26,215 --> 00:02:31,045 And whenever you try to install an app that has a package name matching an 53 00:02:31,045 --> 00:02:32,755 existing app, it installed on the device. 54 00:02:32,965 --> 00:02:36,924 If that signature doesn't match the signature, that was with the previous. 55 00:02:37,575 --> 00:02:39,255 Then Android will object the installation. 56 00:02:39,585 --> 00:02:42,915 And because it's assumed that the signing key, the developer used to sign that 57 00:02:42,915 --> 00:02:46,335 app is generally kept somewhere safe and secure within their own repository on 58 00:02:46,335 --> 00:02:48,435 their computer, or upload it to Google. 59 00:02:48,825 --> 00:02:52,275 Then you can assume that some third party didn't just modify 60 00:02:52,275 --> 00:02:53,685 the app and then upload it. 61 00:02:53,685 --> 00:02:55,095 And then you installed it onto your device. 62 00:02:55,864 --> 00:02:59,075 So that's how Android generally secures updating applications. 63 00:02:59,405 --> 00:03:03,935 The one challenge with that is while it ensures that some outside developer 64 00:03:03,935 --> 00:03:07,445 didn't modify and push an app onto your device, it doesn't guarantee that the 65 00:03:07,445 --> 00:03:11,495 update hasn't been tampered with hasn't had in any malicious or potentially 66 00:03:11,524 --> 00:03:13,265 harmful code within the update. 67 00:03:13,355 --> 00:03:17,195 Like it could still be signed by the original developer, but how do you. 68 00:03:17,855 --> 00:03:19,835 If that update is still safe to use. 69 00:03:19,865 --> 00:03:23,225 And that's generally where firms like now secure come in. 70 00:03:23,225 --> 00:03:26,165 So I wanted to ask you, Brian, can you tell us a bit about the company? 71 00:03:26,495 --> 00:03:26,825 Sure. 72 00:03:26,825 --> 00:03:31,235 Brian: So now secure actually got started as a forensics company in 2008 and 2009. 73 00:03:31,240 --> 00:03:35,405 So the birth of Android that was around the same time as iOS. 74 00:03:36,120 --> 00:03:39,989 Our founder got interested in these cool little devices that seemed to 75 00:03:39,989 --> 00:03:42,600 have a whole lot of computing power and a lot of forensic data on him. 76 00:03:42,930 --> 00:03:46,200 And while he wasn't a forensic specialist, he actually became the world's expert 77 00:03:46,200 --> 00:03:49,980 in mobile forensics and ultimately build a business that is now secure today. 78 00:03:49,980 --> 00:03:53,370 We're kind of an all in one solution provider we have for 79 00:03:53,459 --> 00:03:54,750 mobile application securities. 80 00:03:54,750 --> 00:03:57,299 So we have testing tools, developing tools, pen testing 81 00:03:57,299 --> 00:03:58,940 services, open source tools. 82 00:03:59,395 --> 00:04:02,875 Training all of those kinds of things and partner with lots of organizations 83 00:04:02,905 --> 00:04:06,205 to make sure they're able to deliver those secure applications on whatever 84 00:04:06,205 --> 00:04:07,645 mobile operating system they want. 85 00:04:07,945 --> 00:04:10,825 So our roots are in Android, cuz that's really where he started and we 86 00:04:10,825 --> 00:04:14,245 continue to do a lot with Google and the entire ecosystem community today. 87 00:04:15,200 --> 00:04:15,800 Mishaal: Thanks Brian. 88 00:04:15,800 --> 00:04:19,580 And just to follow up on the Android aspect, one other thing that Android 89 00:04:19,580 --> 00:04:23,450 does at the platform level to protect you is that it has a very secure 90 00:04:23,450 --> 00:04:27,290 model of protecting applications from interacting with other applications. 91 00:04:27,590 --> 00:04:29,510 So you may have heard the term sandbox before. 92 00:04:29,780 --> 00:04:32,960 So whenever you install an app on Android, every app that has a unique 93 00:04:33,140 --> 00:04:36,050 package name, you know, every app has to have a unique package name. 94 00:04:36,080 --> 00:04:38,720 You can't have two apps with the same package name solved on a. 95 00:04:39,594 --> 00:04:43,044 So what happens is that that package is assigned a, a unique identifier. 96 00:04:43,344 --> 00:04:46,104 And when you run that app, Android runs it in a container 97 00:04:46,104 --> 00:04:47,304 and it's called the process. 98 00:04:47,484 --> 00:04:50,575 And then that identifier is called the P I D for that process. 99 00:04:50,815 --> 00:04:53,965 So by putting processes in containers, Android ensures 100 00:04:53,965 --> 00:04:58,195 that apps can only interact with other apps through a well-defined 101 00:04:58,195 --> 00:04:59,935 process called the binder IPC. 102 00:05:00,354 --> 00:05:04,854 So this way apps can only interact and only execute only like send a 103 00:05:04,854 --> 00:05:06,655 request to get data from another app. 104 00:05:06,775 --> 00:05:11,844 Through well defined permissions through well defined, intense and whatnot. 105 00:05:12,085 --> 00:05:14,995 So like you can't just have one app poking around the data of another app 106 00:05:14,995 --> 00:05:18,924 without break the sandbox, which is just not something that is very easily 107 00:05:18,924 --> 00:05:22,375 achievable without some very serious exploit in the Android platform. 108 00:05:22,734 --> 00:05:25,255 I wanted to ask you, Brian, how does this in your experience, 109 00:05:25,255 --> 00:05:29,245 how does Android security model compare to other operating systems? 110 00:05:29,245 --> 00:05:31,104 Would you say it's more or less secure? 111 00:05:31,985 --> 00:05:33,605 Brian: Yeah, that's always a loaded question. 112 00:05:33,605 --> 00:05:36,695 What I would say is that the Linux kernel underneath the Android in and 113 00:05:36,695 --> 00:05:39,905 of itself with its advanced security capabilities, gives it a strength. 114 00:05:40,415 --> 00:05:44,015 Apple has a more closed system on iOS, just in terms of how they operate. 115 00:05:44,405 --> 00:05:46,655 Uh, the sandboxing model is very strong. 116 00:05:46,685 --> 00:05:48,575 You know, the containerization of applications, the 117 00:05:48,575 --> 00:05:50,165 control of the IPC channel. 118 00:05:50,500 --> 00:05:53,590 All of those things are good strengths for Android. 119 00:05:53,890 --> 00:05:57,730 What's been really interesting to watch is that Android kind of was very heavy. 120 00:05:57,970 --> 00:06:00,400 I've been around this since Blackberry, just to be my background. 121 00:06:00,400 --> 00:06:03,280 I was with the original mobile security company called Blackberry. 122 00:06:03,280 --> 00:06:06,550 So I've seen a lot over the years and Blackberry was completely locked down 123 00:06:06,610 --> 00:06:08,020 and completely impossible to innovate. 124 00:06:08,380 --> 00:06:10,810 Just about it all, but it was really secure, right? 125 00:06:10,810 --> 00:06:14,230 And that's an example of a niche user experience with high security, 126 00:06:14,230 --> 00:06:17,200 but it was really inflexible when you wanted to write applications. 127 00:06:17,770 --> 00:06:19,540 The Android world kind of has two communities. 128 00:06:19,540 --> 00:06:21,460 You have the, I just wanna get stuff done. 129 00:06:21,460 --> 00:06:24,130 And then you have kind of the fanboy world I wanna customize 130 00:06:24,130 --> 00:06:26,740 and do really interesting things and, you know, so on and so forth, 131 00:06:26,745 --> 00:06:30,550 which leads to rooting and more customizations in the operating system. 132 00:06:30,640 --> 00:06:33,790 What has been really interesting to watch is that Android has become incredibly. 133 00:06:34,695 --> 00:06:39,344 If you look at the number of CVEs and cess listed for Android operating system 134 00:06:39,344 --> 00:06:43,575 or for device hardware for at least the tier one manufacturers, they have gone 135 00:06:43,580 --> 00:06:46,664 down as a rate over time, apple hasn't. 136 00:06:46,965 --> 00:06:48,854 Now apple may have been a little bit ahead. 137 00:06:48,914 --> 00:06:50,755 So there sort of is this, it depends. 138 00:06:51,375 --> 00:06:55,185 On who your hardware manufacturer is, how they are properly or improperly 139 00:06:55,185 --> 00:06:58,515 using the operating system and the licensing that they're doing around the 140 00:06:58,515 --> 00:07:00,285 play store and the tooling around that. 141 00:07:00,825 --> 00:07:02,625 But Android today is a very safe environment. 142 00:07:02,835 --> 00:07:04,485 And so I live in a blended world. 143 00:07:04,485 --> 00:07:06,705 So I have yes, one of everything because I'm in a mobile business. 144 00:07:07,205 --> 00:07:10,685 I have no qualms about saying which device or which operating system is better. 145 00:07:11,015 --> 00:07:12,965 Android and iOS are both better than windows, frankly. 146 00:07:13,414 --> 00:07:17,104 And so from that perspective, there's lots of different places we can go 147 00:07:17,109 --> 00:07:19,895 in terms of talking about, well, how do I make sure I'm safe and secure? 148 00:07:19,900 --> 00:07:21,275 And how do I make sure I do the right things? 149 00:07:21,875 --> 00:07:22,205 You mentioned 150 00:07:22,205 --> 00:07:24,815 Mishaal: something that I wanna kind of wanted to follow up on power users. 151 00:07:24,815 --> 00:07:27,424 You know, there are people who like the brute and tinker their devices. 152 00:07:27,424 --> 00:07:29,614 That's something that wasn't really possible with the older, 153 00:07:29,614 --> 00:07:32,885 more lockdown operating systems and current ones like iOS. 154 00:07:33,065 --> 00:07:34,565 So on Android, you are allowed. 155 00:07:35,180 --> 00:07:36,530 Side load applications. 156 00:07:36,530 --> 00:07:37,640 This term side loading. 157 00:07:37,640 --> 00:07:40,370 Isn't really much of a thing in the windows world, but it is 158 00:07:40,370 --> 00:07:42,050 something that exists in Android. 159 00:07:42,410 --> 00:07:45,410 And in order to side load, an application from outside of the official 160 00:07:45,410 --> 00:07:49,130 Google play store, you have to opt in, you have to enable permission. 161 00:07:49,130 --> 00:07:51,590 You have to do it on a per application basis. 162 00:07:51,800 --> 00:07:55,670 And there are also other security features that kind of irk power users. 163 00:07:56,000 --> 00:07:59,060 And I wanted to ask you your thoughts first on side loading. 164 00:07:59,060 --> 00:08:00,770 Like how does Google balance. 165 00:08:01,645 --> 00:08:05,185 Ability to allow users to side load applications with actually protecting 166 00:08:05,185 --> 00:08:08,035 them from installing something that's potentially untrusted. 167 00:08:08,485 --> 00:08:08,605 Brian: Yeah. 168 00:08:08,605 --> 00:08:10,285 I think there's kind of two ways to look at it. 169 00:08:10,290 --> 00:08:12,295 So I'm gonna take a macro view and then kind of a micro view. 170 00:08:12,295 --> 00:08:18,055 So the macro view is there are three or 4 billion users of Android, and 171 00:08:18,055 --> 00:08:21,625 that means everybody of every kind everywhere in the world, trying 172 00:08:21,625 --> 00:08:22,705 to do everything you can imagine. 173 00:08:22,975 --> 00:08:23,335 Right. 174 00:08:23,335 --> 00:08:26,125 And so there's lots of different segments of people that wanna 175 00:08:26,125 --> 00:08:27,155 use it in certain behavior. 176 00:08:27,659 --> 00:08:30,960 I do a lot of work with companies that use lockdown, Android tablets that are 177 00:08:30,960 --> 00:08:32,939 purpose designed for a specific use. 178 00:08:32,939 --> 00:08:34,319 They may have one application on them. 179 00:08:35,010 --> 00:08:36,120 I do work in automotives. 180 00:08:36,360 --> 00:08:38,189 I do work in healthcare, right? 181 00:08:38,189 --> 00:08:42,720 And so there's that class financial services where regulatory matters control 182 00:08:42,720 --> 00:08:47,010 matters, sensitive data matters you as a patient, don't want that data lost. 183 00:08:47,280 --> 00:08:49,980 If it's your car, you don't want that car broken into. 184 00:08:50,100 --> 00:08:50,370 Right. 185 00:08:50,370 --> 00:08:51,810 So there's that category. 186 00:08:52,660 --> 00:08:55,840 And then you kind of move into the more general maybe business user. 187 00:08:55,840 --> 00:08:58,720 Then you move into the more generalized consumer and then you move into the 188 00:08:58,720 --> 00:09:02,020 tinkerer category, like the fanboy and you know, and what I think 189 00:09:02,020 --> 00:09:04,810 Google's done a pretty good job of is trying to balance all of them, right. 190 00:09:05,140 --> 00:09:05,949 From that perspective. 191 00:09:05,949 --> 00:09:08,080 And so they've set up the guardrails. 192 00:09:08,444 --> 00:09:11,775 They've continued to improve the guardrails and gates to 193 00:09:11,775 --> 00:09:13,694 make it hard to be malicious. 194 00:09:14,055 --> 00:09:16,275 So you've got the containerized model. 195 00:09:16,275 --> 00:09:20,685 We just talked about side loading to me is an enabler for the category 196 00:09:20,685 --> 00:09:23,025 of people who want it, but most people should stay away from it. 197 00:09:23,475 --> 00:09:27,675 If you were to ask me how do regular people, consumers, not more technical, 198 00:09:27,675 --> 00:09:29,835 advanced customizer, stay safe. 199 00:09:29,944 --> 00:09:30,704 Don't side. 200 00:09:31,155 --> 00:09:36,435 Because Google play with play protect data, safety labels, and all of the system 201 00:09:36,435 --> 00:09:39,555 services that are built into the premium level are designed to keep you safe. 202 00:09:40,005 --> 00:09:42,705 And it's really easy to stay safe when you're leveraging those things. 203 00:09:43,005 --> 00:09:45,435 Side loading is one of the top malware paths. 204 00:09:45,915 --> 00:09:50,655 The other biggest breach vector actually is SMS fishing, and that's not Google 205 00:09:50,655 --> 00:09:52,215 or apple or anybody else's fault. 206 00:09:52,220 --> 00:09:54,465 That's the nature of the way SMS behaves. 207 00:09:54,470 --> 00:09:56,265 And that's a whole different security conversation. 208 00:09:56,535 --> 00:09:58,875 And the fact that people click on that stuff just in the same way, 209 00:09:58,875 --> 00:10:00,255 they sometimes click on spam email. 210 00:10:00,765 --> 00:10:01,035 Right. 211 00:10:01,635 --> 00:10:05,084 So side loading, isn't a bad thing, but side loading can get you in trouble. 212 00:10:05,084 --> 00:10:08,775 So you really should focus on brand name apps from brand name companies, 213 00:10:08,775 --> 00:10:12,795 you know, that have attestation in them with data safety program. 214 00:10:13,485 --> 00:10:17,145 That have four or more stars have millions of downloads, right? 215 00:10:17,145 --> 00:10:20,535 That's just the collective being safe, doing the smart thing, which 216 00:10:20,535 --> 00:10:22,425 is probably 80% of the world really. 217 00:10:23,235 --> 00:10:23,415 Mishaal: Right. 218 00:10:23,415 --> 00:10:27,525 I kind of like in side loading to deciding where to purchase something online. 219 00:10:27,765 --> 00:10:31,125 So if you're a side loader, you're kind of bypassing all the. 220 00:10:31,735 --> 00:10:36,295 Extra scrutiny that is placed on those applications by Google play and by 221 00:10:36,295 --> 00:10:39,295 play protect and all the stuff that's that developers have to go through 222 00:10:39,295 --> 00:10:40,525 to even get their apps on there. 223 00:10:40,915 --> 00:10:43,045 So like if you were to shop online, sure. 224 00:10:43,050 --> 00:10:44,185 You could go to all express. 225 00:10:44,185 --> 00:10:47,365 You could find literally anything you want at any time, but you're 226 00:10:47,365 --> 00:10:50,785 kind of putting yourself at risk by, you know, are you actually gonna 227 00:10:50,785 --> 00:10:51,865 get what you're trying to order? 228 00:10:52,195 --> 00:10:56,425 Is the seller actually legitimate is the product actually as described. 229 00:10:56,850 --> 00:11:00,120 Or could you just do the easy thing and go to like Amazon, you know? 230 00:11:00,180 --> 00:11:00,540 Sure. 231 00:11:00,545 --> 00:11:02,189 There are going to be some fakes. 232 00:11:02,189 --> 00:11:04,590 There are going to pieces of product issues, but generally those are 233 00:11:04,590 --> 00:11:08,280 more vetted because there's more barriers to entry to get on there. 234 00:11:08,610 --> 00:11:08,880 Brian: Right. 235 00:11:08,880 --> 00:11:10,949 You know, a lot of this is risk and reward for the bad guys. 236 00:11:10,954 --> 00:11:11,280 Right? 237 00:11:11,310 --> 00:11:14,790 So those barriers of entry, the friction that's put in the system make it harder 238 00:11:14,790 --> 00:11:18,410 for the people who wanna be malicious to behave malicious and the cost of being M. 239 00:11:18,850 --> 00:11:20,260 Becomes so high, it's not worth it. 240 00:11:20,770 --> 00:11:23,530 So from that perspective, take advantage of everything. 241 00:11:23,530 --> 00:11:27,010 You can buy a first class device from a first class vendor, make sure they're 242 00:11:27,010 --> 00:11:30,850 using they're licensing, Google correctly, and leveraging that technology and so 243 00:11:30,850 --> 00:11:32,140 on and so forth and you can be safe. 244 00:11:32,470 --> 00:11:35,770 And when we look at what Google has done for the two primary safety systems, we 245 00:11:35,775 --> 00:11:38,050 have the play protect side of the house. 246 00:11:38,655 --> 00:11:41,895 We have the data safety label side of the house and data safety labels just 247 00:11:41,895 --> 00:11:43,545 became mandatory in the last week. 248 00:11:44,085 --> 00:11:48,465 And so between those two things, if I can play protect is basically 249 00:11:48,465 --> 00:11:50,595 Google's giant malware engine. 250 00:11:50,925 --> 00:11:53,204 Google is continuously scanning for malware. 251 00:11:53,204 --> 00:11:57,194 Google has a lot of partners that are in security and endpoint management that are 252 00:11:57,194 --> 00:11:59,235 contributing to the malware signature. 253 00:12:00,240 --> 00:12:01,530 While you sometimes see it. 254 00:12:01,590 --> 00:12:04,439 And I'm not saying they're in any it's way better now than it used to be. 255 00:12:04,500 --> 00:12:07,890 And that database allow our signatures and the sophistication of the testing 256 00:12:07,890 --> 00:12:10,800 between Google and Google's partners continues to get better and better and 257 00:12:10,800 --> 00:12:12,870 better take advantage of play protect. 258 00:12:12,870 --> 00:12:14,280 You can run it on your own device. 259 00:12:14,550 --> 00:12:16,830 It's being scanned when it's going into the app store. 260 00:12:16,830 --> 00:12:20,580 If you find something reported and kind of help the community, the data 261 00:12:20,580 --> 00:12:22,500 safety label is really interesting. 262 00:12:22,560 --> 00:12:24,120 So I'll show my age. 263 00:12:24,410 --> 00:12:27,650 I remember when my parents would only buy electronics if they had the 264 00:12:27,680 --> 00:12:32,449 underwriter's laboratory safety label on it, which meant some third party 265 00:12:32,449 --> 00:12:35,180 company tested that piece of electronics. 266 00:12:35,180 --> 00:12:38,150 So it wouldn't like burn you or blow up your house or, you 267 00:12:38,150 --> 00:12:39,079 know, something else like that. 268 00:12:39,740 --> 00:12:43,790 And for the first time, anywhere in software that I have ever seen, Google's 269 00:12:43,790 --> 00:12:45,829 actually added labeling that this thing's. 270 00:12:46,725 --> 00:12:48,135 It's called a data safety label. 271 00:12:48,435 --> 00:12:53,655 And so one half of a label is the software developer is going to attest and say, 272 00:12:53,925 --> 00:12:55,995 here is what my app does with your data. 273 00:12:56,505 --> 00:12:57,105 I transmit it. 274 00:12:57,105 --> 00:12:57,615 I collect it. 275 00:12:57,615 --> 00:12:58,065 I send it. 276 00:12:58,185 --> 00:13:02,865 What have you, the other half is you can get an independent security verification 277 00:13:03,285 --> 00:13:05,355 done by an accredited third party. 278 00:13:05,775 --> 00:13:08,775 And that accredited third party now secures one of them will actually 279 00:13:08,775 --> 00:13:11,925 test it sufficiently to say, yeah, this app is safe based on 280 00:13:11,925 --> 00:13:13,335 this industry standard benchmark. 281 00:13:13,830 --> 00:13:16,410 That's like a good housekeeping seal of approval or underwriter's 282 00:13:16,410 --> 00:13:17,850 lab label on it now. 283 00:13:18,180 --> 00:13:21,480 So now with play protect, I'm protecting myself from malware 284 00:13:21,630 --> 00:13:22,890 with data safety labels. 285 00:13:23,220 --> 00:13:26,610 I'm also ensuring that the app manufacturer is doing the right thing. 286 00:13:27,000 --> 00:13:28,140 And that's really great for users. 287 00:13:28,770 --> 00:13:28,890 So 288 00:13:28,890 --> 00:13:31,320 Mishaal: just to take a step back, because on this show, we love to 289 00:13:31,320 --> 00:13:34,890 talk about a O S P and GMs, and try to differentiate between them. 290 00:13:35,190 --> 00:13:38,520 Google play protect, as Brian had mentioned is part 291 00:13:38,520 --> 00:13:39,480 of Google mobile services. 292 00:13:39,480 --> 00:13:43,370 So it's something that is available on devices with GMs, Android. 293 00:13:43,820 --> 00:13:48,530 So, if you were to compile a S P from Google ski repositories, you would 294 00:13:48,530 --> 00:13:51,980 not have play protect available to you because it is part of, I believe Google 295 00:13:51,980 --> 00:13:55,640 play store app itself, or Google play services, either one of those two. 296 00:13:56,120 --> 00:14:00,620 And as Brian mentioned, it is a massive database of malware signatures. 297 00:14:00,680 --> 00:14:04,640 And I kind of wanted to talk about now, like I wanted to ask you how exactly. 298 00:14:04,945 --> 00:14:07,825 Is that malware signature database actually built. 299 00:14:07,855 --> 00:14:12,535 How does Google go out and decide to add something to its database? 300 00:14:12,835 --> 00:14:15,505 So for the two who looked up anything related to this before you might have 301 00:14:15,505 --> 00:14:18,325 heard terms like static and dynamic analysis, can you walk us through what 302 00:14:18,325 --> 00:14:18,805 Brian: those mean? 303 00:14:19,135 --> 00:14:19,435 Sure. 304 00:14:19,435 --> 00:14:22,165 So there is something called the app defense Alliance. 305 00:14:22,675 --> 00:14:25,555 So I'm just gonna introduce the, how does the data get collected? 306 00:14:25,555 --> 00:14:27,625 So the app defense Alliance was created. 307 00:14:28,079 --> 00:14:29,490 Five six years ago. 308 00:14:29,970 --> 00:14:32,490 And it's a group of folks who do malware. 309 00:14:32,640 --> 00:14:36,449 They do endpoint management, they do antivirus a lot of the subjects 310 00:14:36,449 --> 00:14:38,100 you might expect in this world. 311 00:14:38,130 --> 00:14:41,160 And so Google said, Hey, we wanna crowdsource this stuff. 312 00:14:41,160 --> 00:14:42,000 We've got a whole bunch. 313 00:14:42,000 --> 00:14:42,900 We know you have more. 314 00:14:42,900 --> 00:14:44,160 So let's start collecting them. 315 00:14:44,165 --> 00:14:47,310 So through all of the different vendors who participate in that, when 316 00:14:47,310 --> 00:14:49,980 they find something, they submit it through a special channel to Google. 317 00:14:49,980 --> 00:14:53,130 Google adds it to their database, verifies that the giant database gets bigger. 318 00:14:53,130 --> 00:14:56,339 And it's because there's multiple vendors scanning billions of device. 319 00:14:57,030 --> 00:14:59,310 You get a pretty good signature database as a result of that. 320 00:14:59,790 --> 00:15:03,540 Now, what we're all doing under the hood is we're basically doing 321 00:15:03,540 --> 00:15:07,200 some combination of static and dynamic analysis or SAST and DAS. 322 00:15:07,770 --> 00:15:13,319 And so SAST is basically scanning code either the source code or binary image 323 00:15:13,410 --> 00:15:18,120 of the app to statically identify coding failures in the application. 324 00:15:18,689 --> 00:15:24,360 So with SAST, you might find things like say hard coded secrets embedded 325 00:15:24,365 --> 00:15:28,319 in the application or debugging code that made it into production 326 00:15:28,319 --> 00:15:32,370 in the app store submission or hard coded URLs or stuff like that. 327 00:15:32,370 --> 00:15:33,420 Those are vulnerabilities. 328 00:15:33,420 --> 00:15:33,819 You could. 329 00:15:34,365 --> 00:15:37,515 You can also find malicious behavior, like, Hey, it's scooping up this data 330 00:15:37,515 --> 00:15:39,225 and transmitting it to this IP address. 331 00:15:39,705 --> 00:15:43,245 And then dat, which is dynamic analysis is actually running the app. 332 00:15:43,785 --> 00:15:47,025 Most of us who participate in the program have some sort of dynamic 333 00:15:47,030 --> 00:15:50,385 analysis, which we observe the app running on a real device, whether it's 334 00:15:50,385 --> 00:15:54,255 in a lab or it's on some customer's device that has an agent running on it. 335 00:15:54,255 --> 00:15:56,235 And we see the malicious behavior, we capture it. 336 00:15:56,715 --> 00:16:00,135 So dynamic finds things like permissions, escalation, 337 00:16:00,135 --> 00:16:01,305 because something changes over. 338 00:16:02,145 --> 00:16:05,175 It finds transmission of sensitive data that maybe shouldn't be there. 339 00:16:05,175 --> 00:16:06,735 Is that data properly encrypted? 340 00:16:06,735 --> 00:16:08,415 Does it go to a bad end point? 341 00:16:08,415 --> 00:16:13,395 That's a known malware harvester endpoint from the endpoint databases on the. 342 00:16:13,995 --> 00:16:14,655 Things like that. 343 00:16:14,985 --> 00:16:18,255 So what's interesting about it is the collective is kinda looking for 344 00:16:18,255 --> 00:16:20,835 malware through bad behaviors, but also looking for vulnerabilities. 345 00:16:21,135 --> 00:16:25,245 Some of the more recent issues we found in the market weren't actually malware. 346 00:16:25,245 --> 00:16:28,125 They were vulnerable commercial applications used by millions of 347 00:16:28,130 --> 00:16:31,425 people where the bad guys figured out how to exploit weakness in them. 348 00:16:31,965 --> 00:16:34,625 There was a security weakness that their developers had introduced to. 349 00:16:35,005 --> 00:16:36,925 So that's a little bit about how that works. 350 00:16:36,925 --> 00:16:41,575 Now, the app defense Alliance recently added the MAs specification, 351 00:16:41,575 --> 00:16:44,935 which is that independent security verification strategy. 352 00:16:44,935 --> 00:16:48,775 So this is how to use SAS and dat to analyze the app for vulnerabilities that 353 00:16:48,775 --> 00:16:52,765 could be exploited work with the vendor to fix them, and then give them that good 354 00:16:52,765 --> 00:16:57,265 housekeeping label of approval, which is the independent security review stamp. 355 00:16:57,265 --> 00:17:00,975 So that when you go their data safety label, In the Google play store. 356 00:17:00,975 --> 00:17:04,035 You see, it says independent security review has been completed 357 00:17:04,040 --> 00:17:05,365 by an attested third party. 358 00:17:05,819 --> 00:17:08,190 This is deep save for use in these categories. 359 00:17:08,550 --> 00:17:11,490 And now you have that attestation, which is great from the third party. 360 00:17:12,329 --> 00:17:12,750 So you mentioned 361 00:17:12,750 --> 00:17:15,300 Mishaal: before that, you know, you typically look at either the source 362 00:17:15,300 --> 00:17:19,319 code or the compiled code of an application, and I'm guessing like 99% 363 00:17:19,319 --> 00:17:22,109 of the time you don't have access to the source code of the application. 364 00:17:22,109 --> 00:17:25,139 You're looking for most of the time, you're looking at the binary, the 365 00:17:25,139 --> 00:17:28,139 compiled binary, and you'd have to use some kind of de compilation. 366 00:17:28,949 --> 00:17:32,340 Or some kind of analyzer to analyze behavior while it's on device. 367 00:17:32,340 --> 00:17:34,949 Can you tell us about like some of the tools that you might use? 368 00:17:34,949 --> 00:17:36,149 Are they like all inhouse? 369 00:17:36,330 --> 00:17:36,659 We use any 370 00:17:36,659 --> 00:17:40,649 Brian: commercial for those who are into reversing, you may have heard of Frida 371 00:17:40,655 --> 00:17:45,389 and rod Aari are the top two reversing disassembly tools in the market. 372 00:17:45,389 --> 00:17:48,629 Frida and red were created by researchers on our now secure. 373 00:17:49,629 --> 00:17:51,040 And pancake are their handles. 374 00:17:51,280 --> 00:17:54,010 And so those are used by a lot of security researchers. 375 00:17:54,010 --> 00:17:57,250 They're also used in some other tooling by other folks, and 376 00:17:57,250 --> 00:17:58,480 those are embedded in our tools. 377 00:17:58,840 --> 00:18:02,679 So we can reverse and disassemble an iOS or an Android app, whether it's DRM 378 00:18:02,679 --> 00:18:07,060 or not with it, you can break most of the obfuscation tools and hook the app. 379 00:18:07,605 --> 00:18:10,695 Even the ones that have anti Frita capabilities in it, it's 380 00:18:10,695 --> 00:18:11,685 like a cat and mouse game. 381 00:18:11,775 --> 00:18:13,815 They try to block and then you find new ways around it. 382 00:18:14,175 --> 00:18:17,535 But in reversing it, you can get down to bite code or Java code or some 383 00:18:17,535 --> 00:18:20,895 intermediate language that you can then scan to get a sense from a static 384 00:18:20,895 --> 00:18:22,425 perspective about what's going on. 385 00:18:23,055 --> 00:18:25,755 What I will say is that freedom and Dari are great tools. 386 00:18:25,815 --> 00:18:26,565 Have a look at them. 387 00:18:26,835 --> 00:18:29,445 If you really wanna kinda learn your way through what this world looks. 388 00:18:30,060 --> 00:18:33,990 There's some free training on how to use freedom, Ary and participate in the 389 00:18:33,990 --> 00:18:37,950 community on our academy.now secure.com or you can just find them on the internet. 390 00:18:38,250 --> 00:18:39,090 They're great tools. 391 00:18:39,360 --> 00:18:40,530 There's some other tools out there. 392 00:18:40,530 --> 00:18:42,210 There are various other tools that might go into kit. 393 00:18:42,240 --> 00:18:45,389 You might use perp suite to do network sniffing and some things like that 394 00:18:45,510 --> 00:18:46,830 when you kind of build out a tool kit. 395 00:18:47,159 --> 00:18:49,070 So we leverage those and other advance. 396 00:18:49,330 --> 00:18:50,440 IP that we built. 397 00:18:50,440 --> 00:18:53,680 So do the other vendors have all built something that involves some combination 398 00:18:53,680 --> 00:18:55,120 of static and dynamic analysis? 399 00:18:55,600 --> 00:18:57,880 Mishaal: Speaking of static and dynamic analysis, there is one thing 400 00:18:57,880 --> 00:18:59,140 I wanted to follow up with you on. 401 00:18:59,380 --> 00:19:01,870 And it's something that I think requires some clarification for 402 00:19:01,870 --> 00:19:03,190 listeners who may not be familiar. 403 00:19:03,610 --> 00:19:07,060 And it's that why is dynamic analysis actually important to do? 404 00:19:07,060 --> 00:19:11,500 Why do you have to test on a real device versus why can't you just statically 405 00:19:11,500 --> 00:19:15,340 analyze the code and look for some, say potentially malicious thing happening. 406 00:19:15,700 --> 00:19:21,010 Brian: We talked earlier about containers in IPC and data transmission between 407 00:19:21,015 --> 00:19:22,780 say two containers or two processes. 408 00:19:22,840 --> 00:19:23,110 Right? 409 00:19:23,650 --> 00:19:26,320 Well, that's why you need dynamic analysis, static analysis. 410 00:19:26,320 --> 00:19:29,860 We'll never see if data was improperly transmitted to the IPC 411 00:19:30,100 --> 00:19:31,840 found from one process to another. 412 00:19:32,140 --> 00:19:37,330 You need dynamic analysis to understand what's being written to the device in 413 00:19:37,330 --> 00:19:39,790 log files, or being stored on the device. 414 00:19:40,270 --> 00:19:42,910 We find key material, forensic data. 415 00:19:43,350 --> 00:19:44,250 IP. 416 00:19:44,280 --> 00:19:47,460 We actually found a, uh, coupon code generator. 417 00:19:47,730 --> 00:19:51,510 The actual IP generation of that was spewed out and log 418 00:19:51,510 --> 00:19:53,160 files under error conditions. 419 00:19:53,640 --> 00:19:55,470 Now static source code scanning. 420 00:19:55,470 --> 00:19:58,560 Won't find that you only find that when you run it dynamically. 421 00:19:58,650 --> 00:19:59,730 So it's a general rule. 422 00:19:59,735 --> 00:20:01,700 Dynamic is about testing the crypto. 423 00:20:02,429 --> 00:20:04,199 Is the crypto working correctly. 424 00:20:04,530 --> 00:20:07,439 And then it's testing storage, which is what is being written 425 00:20:07,439 --> 00:20:09,000 and what can I forensically find? 426 00:20:09,000 --> 00:20:12,510 And what's being written into my own address, space, my own storage, 427 00:20:12,540 --> 00:20:16,350 other storage file system log files, and then network transmission. 428 00:20:16,530 --> 00:20:18,750 So what is getting transmitted over the air? 429 00:20:18,750 --> 00:20:19,500 Is it intercept? 430 00:20:20,129 --> 00:20:21,929 Am I doing proper certificate pinning? 431 00:20:21,935 --> 00:20:23,879 Am I using the TLS channel? 432 00:20:23,879 --> 00:20:24,209 Correct. 433 00:20:24,825 --> 00:20:26,445 What endpoints am I talking to? 434 00:20:26,445 --> 00:20:27,765 Are those endpoints safe? 435 00:20:28,095 --> 00:20:30,435 There's a whole bunch of things you can test around authentication 436 00:20:30,435 --> 00:20:33,585 and authorization that you'll pick out through testing dynamically. 437 00:20:33,615 --> 00:20:34,785 So I'll give you wild data. 438 00:20:35,145 --> 00:20:36,795 We scan all the apps in the app store. 439 00:20:37,005 --> 00:20:39,915 So there are 6 million app and Google play store apps. 440 00:20:39,915 --> 00:20:42,795 Approximately we scan almost all of them on a regular basis. 441 00:20:42,825 --> 00:20:46,515 And what I can tell you is that 80% of them have security vulnerability. 442 00:20:47,355 --> 00:20:48,405 The good news is 20%. 443 00:20:48,435 --> 00:20:51,165 Don't have really bad security vulnerabilities in 'em, but 80% do. 444 00:20:51,645 --> 00:20:54,525 And that number's been the same for five or six years since 445 00:20:54,525 --> 00:20:55,665 we've been benchmarking them. 446 00:20:56,085 --> 00:21:00,255 What's also interesting is that when you carve into that static 447 00:21:00,255 --> 00:21:04,935 versus dynamic, almost everything we're finding is dynamically found. 448 00:21:05,355 --> 00:21:08,895 It's really hard to do dynamic analysis and dynamic testing 449 00:21:08,895 --> 00:21:09,915 at scale in a development. 450 00:21:10,875 --> 00:21:12,015 So a lot of 'em just don't do it. 451 00:21:12,255 --> 00:21:15,675 So they run a static analyzer until we find a very low proportion 452 00:21:15,705 --> 00:21:18,495 of static vulnerabilities in production apps, because most 453 00:21:18,495 --> 00:21:19,665 people are using static tools. 454 00:21:20,235 --> 00:21:21,705 Dynamic is really hard to do. 455 00:21:22,125 --> 00:21:25,185 It's expensive if you pay somebody to do it, not a lot of people do it. 456 00:21:25,215 --> 00:21:27,225 And that's why we find that's where most of the vulnerabilities 457 00:21:27,225 --> 00:21:31,455 are in storage in crypto, in network and backend APIs by far. 458 00:21:32,835 --> 00:21:35,745 Mishaal: Yeah, I'm not surprised because you know, they want to avoid detection. 459 00:21:35,745 --> 00:21:39,915 So if you just have all your malicious code statically, it's in the application 460 00:21:39,915 --> 00:21:42,225 itself and it's easy to find, then there's nothing in it for them. 461 00:21:42,225 --> 00:21:44,715 It's, it's gonna be detected and, you know, added to the database 462 00:21:44,720 --> 00:21:47,085 and then detected in the future again and over and over again. 463 00:21:47,535 --> 00:21:50,415 And I've heard stories of like these malicious applications 464 00:21:50,415 --> 00:21:51,855 that behave differently or. 465 00:21:52,585 --> 00:21:55,315 Different parts of code differently, depending on your location or 466 00:21:55,525 --> 00:21:58,225 what device you're running or a combination of those factors. 467 00:21:58,225 --> 00:22:00,255 So like you need to be able to test, and that 468 00:22:00,255 --> 00:22:01,705 Brian: can be hard to find exactly. 469 00:22:01,705 --> 00:22:03,145 It can be hard to find two dynamics. 470 00:22:03,145 --> 00:22:04,615 So, uh, screw an ator. 471 00:22:04,615 --> 00:22:07,495 You're not necessarily gonna see all the IC conversation to the ator. 472 00:22:07,495 --> 00:22:10,765 You're not necessarily gonna see the interaction with the OS layer all the 473 00:22:10,770 --> 00:22:13,375 way down through the hardware or the wifi chip before the carrier chip. 474 00:22:13,435 --> 00:22:13,705 Right. 475 00:22:13,705 --> 00:22:15,295 So what we have found. 476 00:22:16,050 --> 00:22:18,389 For a number of clients who have done emulator based 477 00:22:18,389 --> 00:22:19,440 testing, they bring it to us. 478 00:22:19,440 --> 00:22:20,160 We find stuff. 479 00:22:20,430 --> 00:22:24,210 I mean, you can't truly emulate the environment to get full coverage. 480 00:22:24,240 --> 00:22:26,070 And again, sometimes it's malware. 481 00:22:26,070 --> 00:22:27,600 A lot of it's just vulnerabilities. 482 00:22:27,600 --> 00:22:33,480 I mean, last year, Walgreens slack, they had vulnerabilities that were exploited. 483 00:22:33,600 --> 00:22:36,480 People stole prescription data to the Walgreens mobile app 484 00:22:36,570 --> 00:22:37,830 because of a vulnerability in it. 485 00:22:38,190 --> 00:22:39,210 Slack had a zero day. 486 00:22:40,080 --> 00:22:43,260 So even what you would think would be really great companies. 487 00:22:43,380 --> 00:22:46,380 They can make mistakes, their developers can make mistakes, it might be code. 488 00:22:46,380 --> 00:22:48,390 They write party libraries that put in it. 489 00:22:48,900 --> 00:22:51,540 But what we're actually seeing is the nation state actors and 490 00:22:51,540 --> 00:22:54,660 the criminals are finding these zero days in these applications. 491 00:22:54,660 --> 00:22:57,180 And they're exploiting them as bad or worse as they are the malware, 492 00:22:57,750 --> 00:23:00,570 the price of building malware and getting it into the app store 493 00:23:00,570 --> 00:23:01,830 is getting higher and higher. 494 00:23:01,830 --> 00:23:04,320 Cuz it's harder and harder cuz of everything we just talked about today. 495 00:23:04,800 --> 00:23:06,330 But you know what, if I can find a zero. 496 00:23:07,155 --> 00:23:12,495 In slack and go steal a bunch of corporate data or, you know, shopping cart X and 497 00:23:12,495 --> 00:23:14,115 there's numerous applications like that. 498 00:23:14,115 --> 00:23:18,615 Well, then I can harvest information off of that and use that, you know, there, uh, 499 00:23:18,645 --> 00:23:21,855 if I can diverge for a second, a couple years ago, British airway was preached. 500 00:23:22,305 --> 00:23:25,215 They found a weakness in the way British airways mobile app 501 00:23:25,245 --> 00:23:26,565 was talking to its back backend. 502 00:23:26,655 --> 00:23:29,835 So they learned how to attack the backend by the mobile app. 503 00:23:29,840 --> 00:23:34,215 Then they attacked the backend 380,000 records were stolen, including passport 504 00:23:34,220 --> 00:23:35,805 information, travel history, credit cards. 505 00:23:36,330 --> 00:23:37,200 They were fine. 506 00:23:37,200 --> 00:23:41,850 Bridge share was fined 158 million pounds by the EU as the first GDPR. 507 00:23:41,850 --> 00:23:42,270 Fine. 508 00:23:42,630 --> 00:23:46,830 Now all of that had to do with the fact of a poorly written mobile application. 509 00:23:46,830 --> 00:23:47,670 That was exploitable. 510 00:23:48,090 --> 00:23:49,440 There was no malware involved. 511 00:23:49,440 --> 00:23:52,680 It was just straight up good scientific research that discovered it. 512 00:23:52,680 --> 00:23:54,330 And then they used it to go after the back end. 513 00:23:54,750 --> 00:23:58,020 And that's what we need to think about is mobile's just part of the overall chain of 514 00:23:58,020 --> 00:24:00,150 all the it systems that some company has. 515 00:24:00,555 --> 00:24:03,345 Then you make sure the mobile app and what it talks to is secure, whether it's 516 00:24:03,465 --> 00:24:05,115 malware or whether it's a commercial app. 517 00:24:06,045 --> 00:24:06,315 So this 518 00:24:06,320 --> 00:24:08,655 Mishaal: whole time we've been talking mostly about malware 519 00:24:08,655 --> 00:24:09,975 and like malicious applications. 520 00:24:09,975 --> 00:24:13,995 But if you read online about like what Google pay, protect actually 521 00:24:14,055 --> 00:24:15,915 identifies it, doesn't usually. 522 00:24:16,155 --> 00:24:19,965 Positively identify actual malicious behavior. 523 00:24:19,965 --> 00:24:22,755 It identifies potentially harmful applications. 524 00:24:23,055 --> 00:24:26,955 Can you describe what exactly qualifies to potentially harmful application? 525 00:24:27,465 --> 00:24:31,275 Brian: Yeah, so potentially harmful application is the app is collecting and 526 00:24:31,275 --> 00:24:33,525 maybe transmitting over the error data. 527 00:24:33,525 --> 00:24:37,935 It shouldn't be the app is trying to execute system level commands. 528 00:24:37,935 --> 00:24:39,945 It shouldn't have rights to execute. 529 00:24:40,365 --> 00:24:41,565 It could be spyware. 530 00:24:41,805 --> 00:24:42,915 It could be fishing. 531 00:24:43,260 --> 00:24:44,160 You know, more common things. 532 00:24:44,160 --> 00:24:47,160 We know it could be ransomware in terms of its behavior. 533 00:24:47,160 --> 00:24:50,310 I haven't heard a lot of production ransomware on mobile, but we've seen some 534 00:24:50,370 --> 00:24:52,290 academic experiments along those lines. 535 00:24:52,920 --> 00:24:57,870 Uh, there's a lot of system logging going on, data harvesting going on. 536 00:24:58,290 --> 00:25:01,740 And so what kind of comes back is, Hey, this has some unusual beha, 537 00:25:01,800 --> 00:25:03,210 it's a camera app and it's great. 538 00:25:03,210 --> 00:25:05,640 The entire contact database and shipped it to the cloud. 539 00:25:05,970 --> 00:25:06,270 Right. 540 00:25:06,270 --> 00:25:07,950 And that's gonna get a flag. 541 00:25:08,325 --> 00:25:09,525 If it's picked up, right? 542 00:25:09,525 --> 00:25:12,855 Cause it doesn't make sense that someone who's taking photos is scraping the 543 00:25:12,855 --> 00:25:17,535 entire address book off the device or the history of all the wifi nodes that this 544 00:25:17,535 --> 00:25:21,615 device ever connected to with the S S I D and whatever passwords hashed or not. 545 00:25:22,095 --> 00:25:22,395 Right. 546 00:25:22,425 --> 00:25:26,025 So that's part of what it's looking for is it doesn't make sense that this app 547 00:25:26,085 --> 00:25:31,485 would be doing that thing, whether it's obviously malicious or possibly malicious. 548 00:25:32,385 --> 00:25:32,655 Mishaal: Right. 549 00:25:32,655 --> 00:25:36,945 And another thing is that potentially dodgy and sketchy or malicious behavior, 550 00:25:36,945 --> 00:25:40,995 isn't only limited to apps that you can install from the Google play store 551 00:25:40,995 --> 00:25:42,525 or outside of the Google play store. 552 00:25:42,825 --> 00:25:46,665 It can also be happening within pre-installed applications, which Google 553 00:25:46,665 --> 00:25:48,735 refers to as mobile bundle applications. 554 00:25:49,065 --> 00:25:51,705 This isn't really talked about much from what I can see, mostly because it's 555 00:25:51,705 --> 00:25:53,175 like a conversation Google has with O. 556 00:25:54,165 --> 00:25:57,195 They have like strict requirements about what these mobile bundle applications can. 557 00:25:57,195 --> 00:25:57,945 And can't do. 558 00:25:58,275 --> 00:26:01,155 I wanted to ask you, what do you know about the security risks 559 00:26:01,155 --> 00:26:03,015 with mobile bundle applications? 560 00:26:03,615 --> 00:26:03,735 I 561 00:26:03,735 --> 00:26:04,935 Brian: can't speak for all the carriers. 562 00:26:04,935 --> 00:26:06,015 I can't speak for all Google. 563 00:26:06,020 --> 00:26:08,055 I can't speak for all the device manufacturers. 564 00:26:08,060 --> 00:26:09,195 You need to talk to each of them. 565 00:26:09,195 --> 00:26:11,925 What I would say is that most manufacturers and carriers are 566 00:26:11,925 --> 00:26:13,635 working hard to do it the right way. 567 00:26:14,445 --> 00:26:17,745 So for example, we work with at and T and Google. 568 00:26:18,314 --> 00:26:22,215 And so the things that at and T sells are tested and certified by us. 569 00:26:22,784 --> 00:26:24,225 And we work with a lot of the other carriers. 570 00:26:24,225 --> 00:26:26,205 There are other vendors like us that work with the carriers 571 00:26:26,205 --> 00:26:27,135 to try to do the right thing. 572 00:26:27,139 --> 00:26:31,574 Google has some attestation and testing requirements that the device manufacturers 573 00:26:31,574 --> 00:26:36,254 and carriers must submit, especially if they're part of the Google play ecosystem. 574 00:26:36,615 --> 00:26:38,504 And if they're, you know, full GMs licensees. 575 00:26:39,044 --> 00:26:41,804 And so what they're trying to do is enable lots of people to grow 576 00:26:41,804 --> 00:26:43,905 vibrant businesses and enable. 577 00:26:44,235 --> 00:26:48,135 This very broad ecosystem that we have today that has so many users and 578 00:26:48,135 --> 00:26:49,605 so many kinds of applications on it. 579 00:26:49,995 --> 00:26:52,485 The trick is saying, Hey, here's a set of standards. 580 00:26:52,485 --> 00:26:53,955 We want you to align with. 581 00:26:54,284 --> 00:26:57,195 And we are either gonna test you or have used an independent third 582 00:26:57,195 --> 00:27:00,284 party or self attest that you are doing the right things here and here. 583 00:27:00,524 --> 00:27:03,074 And by and large, everybody's got the right idea and 584 00:27:03,080 --> 00:27:03,945 trying to do the right thing. 585 00:27:04,365 --> 00:27:07,395 You don't hear so much about really bad stuff happening. 586 00:27:08,010 --> 00:27:12,930 I will say that supply chain attacks like we've been hearing in the market 587 00:27:12,930 --> 00:27:16,140 overall on lots of different things, whether you're the colonial pipeline 588 00:27:16,140 --> 00:27:19,260 or what have you, those are out there, and those are hitting mobile, just like 589 00:27:19,260 --> 00:27:20,460 they're hitting other corporate systems. 590 00:27:21,000 --> 00:27:24,300 And so to no fault of their own developers may wind up with an 591 00:27:24,300 --> 00:27:27,690 exploitable or malicious app because of some third party library they're 592 00:27:27,690 --> 00:27:30,870 using or system service they're using that suddenly changed because 593 00:27:30,870 --> 00:27:32,100 a bad actor got in there and made a. 594 00:27:32,895 --> 00:27:35,475 So that will be something I think we're gonna live on in the mobile world, 595 00:27:35,625 --> 00:27:38,835 the web world, the network world, and every other world, until we really get 596 00:27:38,835 --> 00:27:41,985 supply chain management under control and, and more safe use of components. 597 00:27:42,555 --> 00:27:42,765 All right. 598 00:27:42,765 --> 00:27:45,795 Mishaal: So on that front, what can app developers do to protect their 599 00:27:45,795 --> 00:27:47,805 applications from any malicious exploits? 600 00:27:48,254 --> 00:27:49,575 Brian: You know, I think there's a handful of things. 601 00:27:49,575 --> 00:27:52,395 So when we work with organizations who are application developers, 602 00:27:52,425 --> 00:27:54,975 whether they're large or small, we give them a set of recommendations. 603 00:27:55,035 --> 00:27:57,285 First one is make sure you've got some basic security 604 00:27:57,290 --> 00:27:58,455 training for your developers. 605 00:27:58,460 --> 00:28:00,045 Make sure they understand the fundamentals. 606 00:28:00,435 --> 00:28:01,905 Make sure we've got like a guide. 607 00:28:01,910 --> 00:28:03,135 That's like here's 10 APIs. 608 00:28:03,135 --> 00:28:05,535 You should make sure you use and how to configure them properly. 609 00:28:05,595 --> 00:28:07,004 And then a guide on permissioning. 610 00:28:07,365 --> 00:28:09,705 A lot of it has to do with just don't collect and store it. 611 00:28:09,705 --> 00:28:12,315 If you don't need it, then there are things about how to handle storage, 612 00:28:12,315 --> 00:28:15,345 how to handle crypto, how to handle network, how to handle backend API. 613 00:28:15,705 --> 00:28:16,995 They're not very difficult. 614 00:28:17,000 --> 00:28:19,965 In many instances, it's they didn't know there was a flag they should set. 615 00:28:19,995 --> 00:28:22,185 They didn't know there was a configuration option they should be using. 616 00:28:22,185 --> 00:28:24,075 They didn't know there was an ordering of operations. 617 00:28:24,075 --> 00:28:26,595 They should be using, make sure devs doing the right thing. 618 00:28:26,595 --> 00:28:29,505 The second thing is, make sure that there are product requirements that. 619 00:28:30,225 --> 00:28:32,415 What kind of security, this thing should have, right? 620 00:28:32,415 --> 00:28:35,085 If I'm building a banking app, there should be fundamental requirements 621 00:28:35,085 --> 00:28:37,185 that say I'm regulated by the industry. 622 00:28:37,185 --> 00:28:38,235 Here's a set of requirements. 623 00:28:38,564 --> 00:28:40,875 Well, if I'm not building a banking app, we've been building something else. 624 00:28:40,875 --> 00:28:43,245 This requirements may not clear, but just like you're saying, you want a 625 00:28:43,245 --> 00:28:46,574 really cool augmented reality experience, make sure that you're protecting 626 00:28:46,605 --> 00:28:50,004 using multifactor authentication and protecting my Phi while you do it. 627 00:28:50,655 --> 00:28:51,945 Right test it. 628 00:28:52,215 --> 00:28:56,235 Whether you using SAS in the pipeline or SA and da in the pipeline, there 629 00:28:56,235 --> 00:29:00,284 are open source and paid commercial tools that are cheap and easy to use. 630 00:29:00,314 --> 00:29:02,985 They can run autonomously, they catch all the low hanging through. 631 00:29:03,014 --> 00:29:04,064 They make your life easier. 632 00:29:04,395 --> 00:29:07,335 What's really cool about a lot of the DAS tools including now secure. 633 00:29:07,335 --> 00:29:09,314 Now, is it also identifies app store blockers? 634 00:29:09,990 --> 00:29:11,760 So you may have a build version issue. 635 00:29:11,790 --> 00:29:13,500 You may have a third party SDK issue. 636 00:29:13,530 --> 00:29:14,760 You may have some other reason. 637 00:29:14,760 --> 00:29:17,730 Google may say, Nope, I'm not gonna accept this binary because you're 638 00:29:17,730 --> 00:29:18,960 not following one of my rules. 639 00:29:19,110 --> 00:29:20,010 You can catch that too. 640 00:29:20,010 --> 00:29:21,570 So that's not just security and privacy. 641 00:29:21,575 --> 00:29:22,620 That's finding those rules. 642 00:29:23,040 --> 00:29:26,700 And if you're super high end app, you're that embedded health app, that's 643 00:29:26,700 --> 00:29:31,290 maintaining my heartbeat to a cardiac monitor or you're my banking app or 644 00:29:31,290 --> 00:29:32,610 my financial account management app. 645 00:29:32,639 --> 00:29:35,220 You should be doing pen testing once in a while and have really smart 646 00:29:35,220 --> 00:29:37,889 experts, tear it down just to make sure there isn't something exploitable. 647 00:29:38,639 --> 00:29:42,360 So teach requirements, automate your testing everywhere you. 648 00:29:43,230 --> 00:29:44,670 Pen test the high risk stuff. 649 00:29:45,120 --> 00:29:48,900 Be serious enough that say, Hey, we wanna have a great user experience 650 00:29:48,900 --> 00:29:50,700 and millions or billions of downloads. 651 00:29:50,700 --> 00:29:54,150 And we just wanna make sure that people's data does what it's supposed to do. 652 00:29:54,810 --> 00:29:58,080 Mishaal: Security is essential, of course, for every application and developer 653 00:29:58,085 --> 00:30:01,650 should be top of mind, but it should be even more top of mind, especially 654 00:30:01,650 --> 00:30:03,000 if you're dealing with sensitive data. 655 00:30:03,000 --> 00:30:07,830 And as Brian mentioned, medical financial, you don't want to be slapped with, uh, 656 00:30:07,860 --> 00:30:12,540 billions of dollars in a lawsuit for mishandling or having some data breach. 657 00:30:12,815 --> 00:30:15,305 That you could have solved by protecting your application better. 658 00:30:15,665 --> 00:30:20,015 And if you are dealing with any mission critical application or you need to 659 00:30:20,015 --> 00:30:23,795 deploy mission critical applications onto fleets of dedicated devices, and 660 00:30:23,795 --> 00:30:26,495 you wanna make sure that the firmware it's running on and the data you 661 00:30:26,500 --> 00:30:28,475 depend on secured, come talk to us. 662 00:30:28,475 --> 00:30:31,805 That SPER we specialize in helping companies manage fleets of dedicated 663 00:30:31,810 --> 00:30:35,375 devices, including deploying and keeping your apps updated on them. 664 00:30:35,705 --> 00:30:38,165 If you're trying to deploy a kiosk or point of sale terminal, 665 00:30:38,345 --> 00:30:39,125 you need to lock it down. 666 00:30:39,125 --> 00:30:41,555 So potentially malicious applications, can't be side loaded onto. 667 00:30:42,445 --> 00:30:45,415 That's especially important because most of the time, these dedicated 668 00:30:45,415 --> 00:30:47,305 devices won't have GMs on them. 669 00:30:47,365 --> 00:30:50,095 So you can't count on Google, play, protect for protection. 670 00:30:50,425 --> 00:30:53,605 And if you're worried about any mobile bundle applications that are pre-installed 671 00:30:53,605 --> 00:30:57,145 on the off the shelf hardware that you've picked up for your dedicated device 672 00:30:57,145 --> 00:31:00,535 fleet, you'll need to look at deploying your own firmware based on AOS P. 673 00:31:00,865 --> 00:31:01,795 We can also help with that. 674 00:31:02,215 --> 00:31:05,725 Check us out@esper.io and Brian, thanks for joining us on 675 00:31:05,725 --> 00:31:07,075 this episode of Android bites. 676 00:31:07,075 --> 00:31:09,115 Is there anything you'd like to close us off with? 677 00:31:09,115 --> 00:31:09,955 Can you like work? 678 00:31:09,960 --> 00:31:12,085 Can people find you online and work? 679 00:31:12,085 --> 00:31:14,845 Can people work with now secure on securing their application? 680 00:31:15,145 --> 00:31:16,615 Brian: Yeah, so you, you can find us online. 681 00:31:16,615 --> 00:31:17,905 There's a bunch of great resources. 682 00:31:17,910 --> 00:31:18,955 I'm gonna talk out real quick. 683 00:31:18,955 --> 00:31:24,835 So now secure.com/nasa, M a S a that will help you understand the app defense 684 00:31:24,835 --> 00:31:26,725 Alliance and the independent security. 685 00:31:27,554 --> 00:31:30,375 If you're a user look to see that the apps you're choosing have 686 00:31:30,375 --> 00:31:31,395 an independent security review. 687 00:31:31,395 --> 00:31:34,814 If you're a developer, get your independent security review, we 688 00:31:34,814 --> 00:31:36,375 can help you expedite that process. 689 00:31:36,375 --> 00:31:38,024 That's cheap and easy to go do. 690 00:31:38,054 --> 00:31:42,524 If you want some training@cat.now secure.com is a free training environment. 691 00:31:42,524 --> 00:31:46,245 It's for development, QA, DevOps, and security teams to learn everything they 692 00:31:46,245 --> 00:31:50,385 needed to know about building testing and running secure apps in production. 693 00:31:50,925 --> 00:31:52,305 Again, that's a free resource. 694 00:31:52,305 --> 00:31:53,774 You can find me all over the place. 695 00:31:53,774 --> 00:31:55,875 I'm actually known as read on the run is my handle. 696 00:31:56,175 --> 00:31:59,565 So you can find me on, you know, LinkedIn, Twitter, and other kinds of fun places. 697 00:31:59,565 --> 00:32:00,645 Speaking to events of all kinds. 698 00:32:00,645 --> 00:32:03,945 The last thing I'll give you is O O is growing dramatically. 699 00:32:03,950 --> 00:32:06,675 The O OS mobile project is advancing. 700 00:32:07,305 --> 00:32:10,365 There's some really great things coming from O O this fall. 701 00:32:10,365 --> 00:32:12,735 And until later this year with the evolution of the 702 00:32:12,735 --> 00:32:14,115 mobile app security project. 703 00:32:14,115 --> 00:32:18,045 So if you're into the community activities, come join us at OAS, spend the 704 00:32:18,045 --> 00:32:21,675 mobile project and get involved because there's some really great stuff going on. 705 00:32:21,675 --> 00:32:23,385 It's a place you can learn a place you can contribute. 706 00:32:24,000 --> 00:32:25,680 And really be part of a community. 707 00:32:25,680 --> 00:32:27,720 Who's trying to do the right thing for mobile application 708 00:32:27,720 --> 00:32:28,110 Mishaal: security. 709 00:32:28,560 --> 00:32:30,360 And just to clarify, what is O OSP? 710 00:32:30,360 --> 00:32:30,750 Exactly? 711 00:32:30,750 --> 00:32:31,470 What does it stand for? 712 00:32:31,530 --> 00:32:31,740 Oh, 713 00:32:31,745 --> 00:32:35,640 Brian: O OSP is the open web application security project or program. 714 00:32:35,640 --> 00:32:40,770 It's an independent vendor, agnostic community of, uh, security professionals. 715 00:32:40,770 --> 00:32:44,190 Who've been building standards and specifications for how to build secure web 716 00:32:44,190 --> 00:32:49,440 apps, mobile apps, how to secure your APIs on the back end and things of that nature. 717 00:32:49,440 --> 00:32:51,630 So O O for those who are in the security. 718 00:32:52,425 --> 00:32:56,205 Are generally familiar with it as a non-for-profit that drives that 719 00:32:56,685 --> 00:32:59,625 O OSP has a number of initiatives going on in the development world. 720 00:32:59,685 --> 00:33:03,225 And what's really great about it is that Google has fully embraced O O 721 00:33:03,405 --> 00:33:07,335 so the app defense Alliance master certification program, which gets you 722 00:33:07,335 --> 00:33:11,445 that independent security verification actually is using the O OSP standard. 723 00:33:11,835 --> 00:33:14,865 And you're gonna see the O OSP standard in many other places. 724 00:33:15,230 --> 00:33:19,040 As a mechanism for a common industry standard for what security means, whether 725 00:33:19,040 --> 00:33:22,130 it's web mobile network, device or API. 726 00:33:22,460 --> 00:33:24,500 So there's some really great things going on at that 727 00:33:24,500 --> 00:33:25,160 Mishaal: standards body. 728 00:33:25,850 --> 00:33:26,150 All right. 729 00:33:26,155 --> 00:33:26,840 Thank you, Brian. 730 00:33:26,840 --> 00:33:30,380 And thank you everyone again for listening to another episode of Android bites. 731 00:33:30,560 --> 00:33:31,400 We'll catch you next time.