Главная
Study mode:
on
1
Intro
2
SSL Pinning
3
SSL Reporting
4
The Data Set
5
Report Classification
6
Server Misconfiguration
7
Classification Categories
8
Development Proxies
9
Corporate Networks
10
Pins Misconfiguration
11
Spyware Categories
12
What Happened?
13
Spyware - Market Intel
14
Spyware - Ad Blocker
15
Spyware - Parental Control
16
What do we do?
Description:
Explore the world of SSL traffic interception on mobile devices in this 52-minute conference talk from APPSEC Cali 2018. Dive into an analysis of over ten million SSL validation failure reports from iOS and Android apps, uncovering where, how, and why SSL incidents occur globally. Discover various classes of SSL incidents, from well-known corporate traffic inspection to unexpected and suspicious actors. Learn about real-world solutions to protect mobile apps against traffic interception and attacks. Gain insights from Alban Diquet, Head of Engineering at Data Theorem, as he shares findings on security protocols, data privacy, and mobile security. Explore topics such as SSL pinning, server misconfigurations, development proxies, corporate networks, and spyware categories. Understand the implications of SSL interception for mobile app security and discover practical strategies for developers to enhance protection against potential threats.

SSL Traffic Interception on Mobile Devices - Analysis and Protection

OWASP Foundation
Add to list
0:00 / 0:00