This document outlines an agenda for a talk on Android application security vulnerabilities. The talk will provide an introduction to Android security architecture and permissions model. It will discuss how native apps differ from mobile web apps and myths about third party plugins. The talk will also cover how to make apps enterprise ready, demonstrate the top 10 security issues developers face with live examples, discuss tradeoffs of fragmentation, importance of testing before release, and being proactive rather than reactive about security. It will be presented by Subho Halder, a mobile security researcher and co-founder of Appknox.
2. AGENDA
Quick Intro to Android Security Architecture
Android Permission Model
Native App != Mobile Web
Myths about 3rd party plugins
Making your application Enterprise Ready
Top 10 security issues which developers faces with Live Demo
Trade-off between fragmentation
Test before Release
Being PRO-Active than RE-Active
3. ./WHOAMI
Mobile Security Researcher
Co-Founder of Appknox
Creator of AFE (Android
Framework for Exploitation)
Mobile Security Trainer
Part of #droidsec Channel
Python Lover