--- title: "Brian Reed — Mobile Appsec: The Good, the Bad and the Ugly as We Head into 2021" url: https://appsecpodcast.com/brian-reed-mobile-appsec-the-good-the-bad-and-the-ugly-as-we-head-into-2021/ date: 2021-01-06 duration_seconds: 2096 guests: ["Brian Reed"] topics: ["Security Testing", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/8122583-brian-reed-mobile-appsec-the-good-the-bad-and-the-ugly-as-we-head-into-2021.mp3 video: https://www.youtube.com/watch?v=npiHqU2lx4c transcript: true --- # Brian Reed — Mobile Appsec: The Good, the Bad and the Ugly as We Head into 2021 *January 6, 2021 · 35 min* with [Brian Reed](https://appsecpodcast.com/guests/brian-reed/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122583-brian-reed-mobile-appsec-the-good-the-bad-and-the-ugly-as-we-head-into-2021.mp3) · [Video](https://www.youtube.com/watch?v=npiHqU2lx4c) ## Show notes Brian Reed is Chief Mobility Officer at NowSecure. Brian has over 30 years in tech and 15 years in mobile, security, and apps dating back to the birth of mobile including BlackBerry, Good Technology, BoxTone, and MicroFocus. Brian joins us to discuss mobile application security, the good, the bad, and the ugly as we head into 2021. We discuss recent issues in mobile apps, mobile firewalls, mobile vs. web, and how AppSec is different in a mobile world. We hope you enjoy this conversation with... We discuss recent issues in mobile applications, mobile firewalls, mobile versus the web, and how application security is different in a mobile world. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Brian Reed is Chief Mobility Officer at NowSecure. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Brian Reed: → [NowSecure](https://www.nowsecure.com/) → [Mobile Testing Guide](https://mas.owasp.org/MASTG/) Mentioned in this episode: → [NowSecure](https://www.nowsecure.com/) → [Mobile Testing Guide](https://mas.owasp.org/MASTG/) → [Snyk](https://snyk.io/) → [Facebook](https://facebook.com/danondev) Chapters: 00:00 Meet Brian Reed: Brian Reed — Mobile Appsec: The Good, the Bad and the Ugly as We Head into 2021 03:28 It's funny when you think about the architecture underneath BlackBerry. Like 06:55 Let's jump into some of the recent issues that have occurred 11:54 A couple things that you mentioned that I want to dive 16:30 They've made a lot of changes since the days that I 18:57 That's part of the scary, you know, some of the scary 23:20 Yes, that's really easy. It's easy to do too, right 25:53 So when we think about kind of the core audience of 28:36 I mean, I couldn't find anything I disagree with, which, you 29:22 Are the things you should care about 32:22 That's great. It's good information for those people that are going ## Transcript *6,561 words · assemblyai* **0:00 Chris Romeo:** Brian Reed is Chief Mobility Officer at NowSecure. Brian has over 30 years in tech and 15 years in mobile security and apps, dating back to the birth of mobile, including BlackBerry, Good Technology, BoxTone, and Micro Focus. Brian joins us to discuss mobile application security, the good, the bad, and the ugly, as we head into 2021. We discuss recent issues in mobile applications, mobile firewalls, mobile versus the web, and how application security is different in a mobile world. We hope you enjoy this conversation with Brian Reid. **0:34 Robert Hurlbut:** At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term, sustainable security culture amongst all their developers. Our approach is to provide security education that's conversational, quick, hands-on, and fun. **0:52 Chris Romeo:** We don't do lectures. **0:53 Robert Hurlbut:** Instead, we let the experts talk about what's important. **0:56 Chris Romeo:** Modules are quick, 10 to 20 minutes in length. **0:58 Robert Hurlbut:** We believe in hands-on experiments, build or break or style that allow your developers to put what they learned into action. And lastly, fun. **1:08 Chris Romeo:** Training doesn't have to be boring. **1:09 Robert Hurlbut:** We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. **1:17 Chris Romeo:** Hey folks, welcome to this episode of the Application Security Podcast. And on this episode, we're going to talk about something that we don't usually talk a whole lot about, and that is mobile and application security. And so we're joined by Brian Reid from NowSecure. And Brian, we always jump right in. We don't even give you time to catch your breath. We just say, what's your security origin story? How'd you get into this crazy, wacky world that we know of as application security? **1:56 Brian Reed:** That's a good question. So thanks, thanks for having me. My security origin story, I'm actually a biomedical engineer by trade and was writing software to do digital imaging way back in the '80s. You can tell that I'm that old with my gray hair. And I caught the bug on the coding and IT side and never was a BME anywhere in my life and was living in Research Triangle Park. So the technology was, was real hotbed down there. But over a series of different companies I worked for, eventually I landed with a partner of BlackBerry's, and that's where my mobile and my security origin really comes from. So if you think of BlackBerry, not only was it really the first smartphone, it was also built from security on the ground up. And so my mobile baptism was in that highly secure-oriented world, and that was when, you know, basically mobile was email on this cool device, and if you were an executive, you had to have one. And it was like addictive, you know, like SMS texting or instant messaging is today. And so, you know, working with BlackBerry as a partner was a big deal. We worked with a lot of organizations. Eventually we got into building apps around the BlackBerry ecosystem as it evolved and welcomed applications, and that's just it. So I caught the bug over 15 years ago. It's hard to believe that, you know, BlackBerry is like 20-some years old, and now have been working in a variety of different mobile and application and security type vendors or organizations for the last over 15 years, and that's what brought me to NowSecure. **3:28 Chris Romeo:** It's funny when you think about the architecture underneath BlackBerry. Like, I think BlackBerry switched to— I don't know if they've moved to Android now, but I remember like government evaluations and things looking at the BlackBerry operating system and just being in awe about how secure it was. They really did think about security from the inside out. And it's almost like we've gone back a little bit in our modern day, right? So like, you know, Android and iOS have a lot of good stuff, but we've kind of moved backwards a little bit architecturally. **3:58 Brian Reed:** Yeah, well, it is kind of interesting, right? So, you know, when, when a system is purpose-built from the ground up to do a single thing, you know, you can build it very efficiently, right? And, and what we've done with modern mobile is we've moved from a single-purpose email machine, which was really the BlackBerry, into email plus some other, let's call it system services like BBM with messaging and some other things, into a general-purpose operating system upon which people can build all kinds of interesting experiences, right, which is what we call applications. And the more you make it flexible to build cool new things, the more you frankly weaken the underlying architecture potentially from a security and privacy perspective if you're not careful. We went through this arc where Android was massive freedom and openness, and Apple was completely locked down and curated. Through that arc now, they're similar to each other in where we are in the arc, but we've also built some really amazing things. Whether it's the Roomba running around your house, or the Ring doorbell on your house, or the fact I can call an Uber, or even more strangely, I can order McDonald's and have Uber Eats deliver a McDonald's to my house. I mean, all these things that happen now. I got a Tesla a year ago. I can summon my Tesla. I can pull it out of the driveway. It can drive itself, right? And using a mobile app to do it. It's been pretty amazing to see how it's all evolved. **5:23 Chris Romeo:** And that just reminds us once again, the impact of the threat landscape on mobile is so crucial because you just described a world where your car's driving down the street using the technology on your phone as the driver or the— what's controlling it. And so if we don't get security right, we're gonna have big problems. And it sounds like you're saying mobile is gonna have a big role to play in that world of the future of security. **5:50 Brian Reed:** Yeah, well, I think the interesting thing about mobile is you reflect on it as mobile is the thing with you always now, right? 20 years ago, you wouldn't leave the house without your keys and without your wallet. For a lot of people, it's just the mobile device. The mobile device is the key. The mobile device is the payment token and all the rest. And so we're kind of in this digitally addictive, connected world where, yeah, I have a desktop and a laptop and all that stuff, and I do my higher-end work on that, but most of the rest of my life is in and around that mobile thing. And that mobile thing is a walking, a walking intelligence hub. It's a walking attack vector, right? That's got this attack surface that's really quite porous. And from that perspective, that's kind of why I'm in the business I'm in now in working with NowSecure, because we work with, you know, companies like Uber and these big organizations who are mobile first or going through mobile digital transformation because they know their customers and their employees are living on it. And they gotta figure out how to protect themselves from these apps that basically just run in the wild in an unpredictable space that isn't a locked-down laptop the company gave me. **6:54 Chris Romeo:** Well, let's jump into some of the recent issues that have occurred in the mobile space. And I know we were talking in advance about a couple of different things, Sourmint, TikTok, Dave, and even a study that Comcast has done. Let's go ahead and start with Sourmint. Sour Mint. I mean, what a great code name for a vulnerability, right? **7:14 Brian Reed:** Yeah. **7:15 Chris Romeo:** Sounds like candy. I want to get some candy, but I know it's not candy. **7:19 Brian Reed:** It does. So the folks over at Snyk were doing some research along with our CTO, and they found that a third-party library that was being used was actually harvesting information off of devices and sending it back to data collection servers. And, you know, that's not an uncommon thing, sadly, that we find. Sour Mint was particularly egregious in what they were harvesting and how they were collecting it in an unknown way. And then we, you know, once, once they found it, we went and looked at our database. We scan millions and millions of apps in the iTunes and Google Play app stores, and we do that as a service, and that creates a great data lake for us to really understand where mobile risks are. And we instantly found there are some 1,500 mobile applications that were at risk that were using this particular SDK. that exposed this vulnerability, this exploitable vulnerability. And so Sourmint is that example of make sure you choose carefully for your third-party libraries, right? And this was not open source, that was commercial library that was in there. You know, you roll backwards this summer, we were talking about banking, right? So I said that, you know, the mobile device is now your wallet. Well, we see a lot of interest, especially in the younger generations, in mobile digital banking. There was recently a piece in Forbes that talked about how the millennials are either using these newfangled apps, or they're going back to the big guys like the Citigroups and so on and so forth, Bank of America. The big guys have big security teams and have really great bulletproof features and software. Well, this summer, there was a breach in one of these little mobile-only banks called Dave. The app's called Dave. I don't know why you'd call a bank Dave, and I'm not making fun of the name, but I thought that was interesting. They had a breach. That can happen. When, you know, the manufacturer of the app is smaller, maybe they have a less sophisticated security team. You know, the big global banks have thousands and thousands of security people. If Dave's online mobile bank has a couple thousand employees, how many are in security? Are they doing the right things? Do they have the right skills? You know, that's kind of out there. And so today in the mobile world, there is no public certification that says this is a safe mobile app or not, right? So we get these kind of whack-a-mole games. You get something like TikTok, and TikTok is a political hotball, it's all kinds of stuff. TikTok itself, it harvests data like every other social media app, Facebook, and Twitter, and Instagram. Those guys are harvesting a lot of intelligence off your mobile device. If you're using Facebook's authenticator, or any of those other authenticators, they're gaining a lot more information as well. You may remember earlier this year, Zoom had a little challenge, and You know, we were happy to work with Zoom when they had this massive explosion of use when we went into lockdown. And they had basically fat-fingered their use of the Facebook social login capability. And they didn't— they were using the social login to provide a great feature, though when the developers encoded it, they didn't properly lock down to just use it for auth. So they were actually sharing data back with Facebook in an unknowing way. And so even when people intend to do the right thing, they still have to be careful. in how they build their mobile apps, how they use these libraries, and so on and so forth. And then the, you know, the consumer has to figure out how do I decide which ones to use. So to circle back to TikTok, so TikTok is no worse in harvesting data than any of the other guys, right? And I'm not a big social media user. I am on Twitter. I think a lot of good security people are, but I don't use Facebook. I don't use Instagram and the other guys, in part because of the data harvesting. Now, just because they're doing the same thing all the other guys are, I think the bigger concerns are what's going on in the backend with the data. data. None of us really know what goes on in the backend with the data. We know that companies like Facebook are monetizing it. Twitter is somewhat monetizing it, but Twitter is also a communication channel that a lot of people use in a lot of ways. The story arc basically now is that here we are in Comcast, who releases their data every year in the fall. Comcast has internet— excuse me, Comscore, not Comcast cable company, Comscore, has internet sensor data, and they track usage of time and data on the internet. They just released a few weeks ago their latest data that shows that 70% of all digital time is spent in mobile apps, not on the web, not in mobile browsers. If we think about that, that's probably true. I bet everybody who's listening to this spends a fair amount of their day in mobile apps, depending on who you are and your age, more or less. **11:53 Chris Romeo:** So a couple things that you mentioned that I want to dive into a little bit deeper there. One is architectural, one is being able to understand if there's any type of standard. So let's go there first with the standard. You mentioned there is no certification for mobile apps. Have you heard or seen anything? Are there any movements in the industry to say that we're going to do some type of a security certification for these? Because I know App Store from Apple, Google Play, they have testing and they have standards and things that people have to comply with. And there's— it's always a cat and mouse game because there's always, you know, new people trying to sneak stuff in and them trying to check it. But are you hearing anything in the industry that says we're going to have some type of a seal of approval for an app that I can use on my phone? **12:37 Brian Reed:** That's a good question. So, there's standards and then there's seal of approval. So, we do believe that the rise of risk in the attack surface, the rise of breaches, will align with the need for standards and the demand in some way, shape, or form for more certification. We're seeing it in a couple specific places and then one generic. So on a specific case, the federal government in the DOD is now mandating something called NIAP, N-I-A-P. NIAP is a set of standards requirements originally created by the NSA and NIST. And it's actually— there's many governments around the world that have also signed on to NIAP. So we are seeing— **13:16 Chris Romeo:** Okay. **13:17 Brian Reed:** that federal agencies are turning to NIAP as a standard. It's a specific way you must vet a mobile application. It has 51, 52 points of criterion that have to pass. And there's automated software like NowSecure, there's third-party testing companies you can hire to do it or what have you. So that's there, and that may or may not bubble into the civilian world. What we are seeing from a lot of our mobile-first companies, especially in the high-risk space, Is they're looking to either industry-specific requirements. So, you know, how would HIPAA evolve in healthcare to potentially affect me? If in medical IoT, there's some US federal regulations as well. And we can kind of walk our way through the banks and other verticals. So there's pieces of requirements, but they're generally around compliance, which isn't sort of the same as certification. What we do see happening is the mobile security program at OWASP has grown dramatically in the last 2 years. And so, you know, we've been contributing since the OWASP Top 10 for mobile, and the OWASP mobile program now has the MSTG and the MASVS. The MSTG is the testing guide, and the MASVS is basically how to build a secure app. A lot of organizations are turning to that as a standard, and I think over the next 2 years we're going to see the haves and the have-nots And the haves are going to be the ones that are going to use the MSTG as a testing standard. And I'm willing to bet lightly in Vegas that it won't necessarily become a minimum bar, but it'll become a premium bar. That, you know, for organizations who want to show that they're safe and secure and private, they'll use something like the MSTG and, you know, brand themselves that they're MSTG compliant in some way, shape, or form, I think, to kind of help move the ball and it can become a competitive differentiator potentially for their business. **15:12 Chris Romeo:** Even though OWASP doesn't, will never provide a seal or a certification. **15:17 Brian Reed:** No, it's not a seal, but it's at least, the nice thing about it is a really good community who's been contributing to it very actively over the last couple of years. And the MSTG is a very robust standard. It's a challenge to fully certify an app for everything in the MSTG. So you'll find there's kind of levels that people will look at, but it's at least a common way to say, hey, if I, if I have passed all the MSTG tests, or if I passed the Level 1 MSTG tests, you know, I meet certain bar, certain minimum bar criteria. And that will get us without certification, at least get us to a common, a common defense level. **15:53 Chris Romeo:** Yeah, you mentioned NIAP, so you're making me nostalgic here. So I got my start in security doing Common Criteria and government trusted product evaluations. So I was part of the team that did the first Common Criteria evaluation from a commercial entity working with NSA and folks from NIST and stuff. So yeah, it's like, you know, we're going back to the late '90s here, like it's nostalgia day. **16:17 Brian Reed:** The Mobile Protection Profile rolled out in 2017. It's gone through a couple of evolutions, and now there's both third-party services and commercial software like NowSecure that can certify for it, which is great. **16:29 Chris Romeo:** Yeah, that's awesome. **16:30 Robert Hurlbut:** I love— **16:30 Chris Romeo:** they've made a lot of changes since the days that I was rolling around there. Another question I had for you, and this is, you know, completely off the script, but from a mobile architecture perspective, I'm just wondering from your perspective as someone who's thinking about mobile all the time, I think about an app like Facebook. Okay. And we all know that Facebook is harvesting various data and pieces like that. Why can't somebody write a privacy wrapper that sits around an app like Facebook or other things, and it's almost like a personal firewall on a per-app-by-per-app basis. What prevents that from being a new type of product or a new type of market or something? **17:11 Brian Reed:** I'm going to slice that into a couple of things. I think from the privacy perspective, Apple's taken the lead in really evolving iOS with further and further controls and lockdowns. And they are now, as part of the App Store approval process, looking at privacy more carefully. **17:28 Robert Hurlbut:** Mm-hmm. **17:29 Brian Reed:** So I actually think that containerization model, and that is the foundation of iOS, that Apple keeps layering into now around privacy, plus some of their general policies, are going to help. And so at the operating system level, we're getting to a point where more and more privacy will be possible. And so part of that, though, typically has user opt-in controls. So just because privacy is there doesn't necessarily mean the user's opted in, right? **18:00 Chris Romeo:** Right. **18:00 Brian Reed:** So that means we need to be smarter consumers in terms of how we configure the apps. Your idea of a wrapper or a container-y thing, there are some container technologies out there. I was part of a company called Good Technology that was kind of the de facto standard for containers. There— people have been trying to build wrapper technologies on and off over the years. There are some out there now that have some level of protection. The challenge usually for those is you either need to have the source code or you need to have control of the binary in order to do that. So, you know, you as the home user of a commercial Facebook app, there's really no way for you to deal with that. It's either Facebook would have to put it in there or, or someone would have to jump through hoops. So I think some of that, we just have to continue to rely on Apple and Google to continue to put controls and restrictions or options in the operating systems, you know, to help us do that. **18:57 Chris Romeo:** That's part of the scary, you know, some of the scary part is we're talking about putting Apple in there. I mean, I'm a huge Apple person. I've got hundreds, seems like hundreds of Apple devices around me. But yet, do I trust Apple is the question? You know, there's been this thing with like, I don't know if you've seen, and we're diverting from mobile now, but this thing, this issue where people are alleging, I haven't looked at the data, so I'm just saying alleging at this point, but that Mac apps are phoning home. **19:25 Robert Hurlbut:** Mm-hmm. **19:26 Chris Romeo:** And in Big Sur, there's been an architectural change, the latest version of the operating system, so that like software packages that would have blocked that type of communication in the past, those channels are going below the layer where a third-party piece of software could block a network request going outside of the system. And so I guess, you know, that's just my only— I mean, I love the fact that Apple is more privacy-centric and they're going to be able to protect us better from the phone perspective, but I think we just got to get to a point where, like, you know, who's watching the watchers is always the question. **19:55 Brian Reed:** Well, you know, I do think that Apple and Google both mean well, right? So in working with both their teams, you know, they both believe a lot in security and privacy. Google's come a long way in their security advancements. And I think one of the recent pieces of Gartner research, some other third-party research shows that it's arguable whether iOS or Android is, you know, more secure than the other. I do think iOS has the lean on the privacy, and Android has some advantages as well. But it's going to be a cat-and-mouse game. I think that, you know, a lot of this gets back to I'm going to say it bluntly, you can't trust anything. You got to make sure the apps themselves and the communication channels those apps are communicating on are hardened. **20:41 Robert Hurlbut:** Yeah. **20:43 Brian Reed:** If the app is doing the right thing, if the app is managing its own data the right way, if it's using safe libraries, if it's using the appropriate APIs, if it's locking itself down using advanced encryption, if it's got app hardening in it, if it's doing cert pinning and cert validation when it's communicating with backends, etc., etc., etc., etc., and that entire attack surface is getting continuously tested, examined, and monitored, you know, then it basically becomes a self-defending application that can live in any kind of these wild-oriented scenarios. **21:14 Chris Romeo:** So let's kind of change gears a little bit, and we were going to talk about kind of the mobile versus web, how mobile and web are not the same. And so I'd love to get your perspective on why are you saying they're not the same? How are they different? Remember that question from elementary school, compare and contrast. These two things. **21:34 Brian Reed:** Yes, yes. Why is the horseless carriage faster than the horse? So mobile and web, there's a couple of fundamentals to the difference between mobile and web, and I think when people come to mobile, most people who come to mobile, whether you're a developer or an IT administrator or something else, you're coming from a web or a PC-centric native application background. And there's a set of fundamental differences between mobile and web that kind of create this different attack surface that developers and security people alike have to understand, right? So if you think about a web app, generally a web app has 98% of its code behind a firewall, right? So you've got layers of perimeter defense there. You're not going to put all that code if you can help it— the code, the logic, and the data— you're going to move as much of it as you can behind the web server, right? Which gives you more layers of protection. Now, it's sad that the web world's still one of the top vulnerabilities of cross-site scripting, but, you know, you can solve the XSS problem if XSS problem if you're doing the right things. When you're a web developer, then security is there. When I'm in the browser, all I need to do is call HTTPS and SSL turns on. The browser itself can control whether it can write to disk. The browser has its own memory workspace, and so on and so forth. To a large extent, the web app, what's resident on the local machine is in a containerized environment. Now, some browsers have more lockdown capabilities than others, but as a general rule, as long as I'm doing the right thing, Right? I'm keeping the most important IP behind the firewall, and, you know, I'm using SSL. I'm pretty well protected. When you get to a mobile app, it's complete Wild West, right? So if I'm a mobile application developer, I'm running on a device, an iOS or Android device, and my app is reversible. There are reversing tools that will reverse any iOS or Android app. **23:19 Chris Romeo:** Yes, that's really easy. It's easy to do too, right? It's like, it's not, you know, it's not even like it's hard. Like anybody can download this, this, grab an app from the App Store and run this, this program against it. **23:30 Brian Reed:** Right. Frida and Radare are 2 examples of mobile reversing and mobile security tools that were created by our security researchers that we use in our products, and a lot of people use those commercially as well from a research perspective and a pen testing perspective. You can reverse it, and then they're going to model the application. But what winds up happening is, as a developer, I have to understand how to build a secure connection to the backend. I have to understand how to do certificate pinning. I have to know that I need to do hostname validation. I have to know how to do encryption. I have to know how to do local data storage. I have to think consciously about what am I going to store locally or not, etc., etc., etc. So you have the combination of most of your logics in the wild and reversible on the client to— I also have to have a lot more skills when it comes to handling data in motion, data in rest, data storage, those types of topics. And so what we tend to find when we, when we work with organizations and they maybe have poorly scoring apps, it's developer ignorance. Not ignorance in a bad way. Ignorance is, I didn't know how to do that. I didn't know how to do proper connection management. I didn't know how to do proper data storage. And so that makes it a challenge to build a secure app. And so now you've got this attacker-rich environment combined with a world where not all developers have all the security skills they need. to build secure code, and that's what makes it such a breeding ground now. And if you go to that Comscore data that says 70% of all traffic is mobile apps, well, that's a rich zone for bad guys to go after, right? And, you know, cybercriminals, nation-states, whatever, you can assume that at scale they are mass reversing and analyzing your apps in the App Store. If you are any kind of a target that has any kind of useful IP, Or you have, you know, customers, transactional information, credit card information, PII, anything like that, your app's already been reversed and modeled somewhere by one or more, you know, cybercriminal or government agencies, nation states. So you need to think about that, and that leads to secure coding practices, that leads to using good secure third-party libraries, that leads to architecture. There's a whole lot of things more than did I just create a really cool app. that people have to think about with mobile that's different from web. **25:53 Chris Romeo:** And so when we think about kind of the core audience of people who are listening to this conversation right now that are playing in the application security space somewhere, they may or may not have responsibility for mobile, but it's a good chance that their organization has mobile apps. Maybe they're not the ones that are directly looking at them, but what would you recommend for those AppSec professionals What do they need to do differently when they're thinking about all the things they know about web and kind of translating or transferring to mobile? **26:24 Brian Reed:** Yeah, so, you know, a handful of things. At the NowSecure website, you can find a What's the Difference Between Mobile and Web and What Do I Need to Know guide, so feel free to hit that up. That's a short version of what I'm about to go through. You know, we tend to find there's sort of 3 key things people should look at. First one is, if you're on the developer side, download and read the MASVS from OWASP, and if you're on the tester side, download and read the MSTG. You will learn a ton in that process, and because it comes from OWASP and the community, there's a lot of analogies provided in there about, well, in the web world it was like this, but in the mobile world it's like that. And so they are a tome, it's a couple hundred pages, But that's really the definitive, you know, guide to understanding that. And then there's thinking about, you know, what's your strategy yourself if you're a tester, for example, and what's your strategy with your engineering team, right? So thinking about how secure mobile development best practices are gonna be shared and learned with your development team is very important. We find that the better application security teams have a good relationship with their developers and are helping feed them with secure coding best practices and resourcing like that. And if you're a pen tester, you know, get involved in the community. There's a lot of, you know, we run like the 4-day mobile pen testing class at Black Hat every year, and people love it. You know, it's kind of a line out the door. It fills up on the first day because we see that people really want to learn, right? And so there are resources out there. If you're an open source tooling person, go have a look at Frida and Radare, very active communities around those open source tools. for reversing and instrumentation. You know, people who are kind of black belts in mobile security will be using tooling like that. There's plenty of other tools in there, Minimum Proxy, Burp Suite, and so forth for your network testing and all of that. And, you know, I think overall, if you're building software, you need to think about what's my on-demand testing model, what's my continuous security testing model, what's my pen testing model, and ultimately Do the appropriate level of threat modeling and risk modeling in your mobile apps, and then make sure you're building in the right kind of testing strategy. Definitely. **28:36 Chris Romeo:** I mean, I couldn't find anything I disagree with, which, you know, I was hoping for at least one thing where I could be like, now, come on, Brian, really? You want to do that? But I've got nothing there. And you even ended with my favorite thing, threat modeling. So when you think about, you know, kind of, I'm not going to say, I can't say shift left, I can't say it. I can't say it. I've labeled it a marketing term from now on in my life. And so I'm going to— I'll just say, you know, as people are thinking about using DevOps with a mobile versus web, what are some of the things like if I'm— if I've got a couple mobile apps, but I've got a really mature DevOps approach for my web apps, and now I'm getting into DevOps and mobile, what are a couple of things I should think about? **29:21 Robert Hurlbut:** What are the things you should care about? **29:22 Brian Reed:** Yeah, no, it's really good. So, you know, the first thing is if you are running an effective web security program in DevOps, so I'm not even going to use the word DevSecOps yet, I'm just going to say I've got a good web security program. **29:33 Chris Romeo:** I don't use that word anymore either. **29:35 Brian Reed:** You probably have at least 2 things you're doing, right? So the first thing is you probably have a SAST tool that's doing some level of scanning. And while SAST source code scanning will throw off a lot of false positives, that's at least going to help you find low-hanging fruit and and kind of raise your bar on security. You should also be doing something around SCA. So you should be looking at your open source libraries and understanding where your risk is on open source and third-party libraries. We find that is a primary weakness attack vector and sort of malware vector in mobile. And so at a minimum, you ought to be doing those 2 things, right? So I'm scanning my code all the time, whether it's third-party open source code or the code that I write. When you get to mobile, it's kind of interesting because in benchmarking those millions of apps and kind of correlating them with what testing tools we've surveyed and discovered, you know, many of these organizations are using, what we actually find is source code scanning only finds about 20% of the real-world vulnerabilities that are discovered. **30:29 Chris Romeo:** Mm-hmm. **30:29 Brian Reed:** And so while mobile— while web, you might be able to depend heavily on source code scanning, in mobile, it's actually best practices to do binary scanning of the compiled binary because that's what the attacker's attacking. And you never know how that source code is gonna compile down into a real application. So state-of-the-art in mobile is actually DAST and IAST. And so statistically, if you analyze those millions of apps, you find that DAST finds about 50% of the vulns, IAST finds another 20 to 30% of the vulns, and then backend API security testing, which is making sure the backend part that the mobile is talking to is— also needs to be scanned as well. And so what you'll see is there's a group of companies like NowSecure that come from the mobile binary testing world. None of the big guys, the traditional security guys like Veracode and Checkmarx and those guys, you know, they're not built to do high-volume, deep mobile app-specific analysis. And so when you think about your strategy, you should still test your SCA open source. You should still SAST source code scan. But the big thing for mobile is you need to add DAST, if not more than DAST, getting into the IAST space. And on mobile, you need to test the binary, not just the source. And so that becomes either an on-demand thing, right? So you may have pen testers. What's pen testing? Pen testing is dynamically testing an app, frankly. So you could have humans do it and they do it periodically. You can license on-demand software to do it, right? And then a developer can submit it or a tester can submit it, or you can build it into the pipeline. And there's, there's plenty of tools that plug into Jenkins and Jira and Azure DevOps and GitLab and GitHub and all that tooling that will do it in the background as a continuous security testing kind of model. Every build you get generates another test run, as it were. **32:21 Chris Romeo:** That's great. It's good information for those people that are going down that path of trying to catch up their mobile environments to what they're doing from their web applications. So when you think about kind of concluding our conversation here, What's one or two calls to action? Like, we love to leave our audience with something to do, you know, give them some homework, send them to do something like, you know, in case they tuned out for the last, you know, they were listening, they tuned out, they're coming back, wake up, and Brian's about to give you a call to action with some homework to do. So, what would you say? One or two things? **32:58 Robert Hurlbut:** Yeah. **32:58 Brian Reed:** I'm sorry, I'm gonna make it 3. So, the first one is, if you wanna go make money, become a mobile pen tester or a mobile security expert. There is a Derth. You know, I talked about 70% of the world is now using mobile apps, but only about 10% of application security people can do mobile. So there's a huge job opportunity for you to build your skill sets, and we're seeing that you get paid more. So mobile security experts often get a premium, and so that's the first thing to think about. I think the second thing is if you're an open source hound, get a look at Frida and Radare and get involved in the mobile security open source community. I think that's well worth looking at. And then the third one would be, you know, when you, when you think about getting smart, again, I'll go back to the OWASP resources. The MSTG and the MESVS are really good learning resources, and there's lots of practical resources wrapped around them. You can find a lot of training videos and explanatory resources at the NowSecure website around OWASP to kind of help you flesh that out. And, you know, so those all become resources, you know, to take advantage of depending on where you are in your security journey. **34:06 Chris Romeo:** All right, well, Brian, thank you so much for sharing your expertise with us and with our audience here, and we'll definitely have to do this again in 6 months or a year. And I've got a million other questions about mobile, but I'm going to save them for another day. **34:19 Brian Reed:** This is great, Chris. Thanks for having me along today. **34:21 Robert Hurlbut:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/brian-reed-mobile-appsec-the-good-the-bad-and-the-ugly-as-we-head-into-2021/