Mobile security essentials
Details
OWASP North Sweden is proud to welcome Sven Schleier and Jeroen Willemsen, two co-authors of the OWASP Mobile Security Testing Guide and the OWASP Mobile AppSec Verification Standard. The talks will discuss techniques and tools related to building and testing security in mobile applications.
The event and all presentations will be held in English. Please state any dietary preferences in the RSVP.
Agenda
17:30 Event starts with a light snack
18:00 A word from event sponsors Acino, Codemill and Omegapoint
18:15 Sven Schleier - OWASP Mobile Security Testing Guide (MSTG)
19:00 Short break
19:15 Jeroen Willemsen - All about the keying material
Approx. 20:00 Event ends
Sven Schleier - OWASP Mobile Security Testing Guide (MSTG)
This presentation will give an overview of the OWASP Mobile Security Testing Guide (MSTG), Mobile AppSec Verification Standard (MASVS) and Mobile AppSec Checklist documents. The OWASP Mobile Security Testing Guide recently reached 1.0 status last year and will be available as a printable book sometime this year. The vision for the project is “[..]writing a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.”
Sven is an experienced penetration tester and security architect who specializes in implementing secure SDLC for web application, iOS and Android apps. He is a project leader for the OWASP Mobile Security Testing Guide and the creator of OWASP Mobile Hacking Playground. Sven also supports the community with free hands-on workshops on web and mobile app security testing. He has published several security advisories and a white papers about a range of security topics.
Jeroen Willemsen - All about the keying material
This talk will cover the use of certificates, certificate pinning and storing cryptographic keys etc. securely in iOS and Android.
Jeroen is a full-stack developer specialized in IT security at Xebia with a passion for mobile and risk management. He loves to explain things: starting as a teacher teaching PHP to bachelor students and then move along explaining security, risk management and programming issues to anyone willing to listen and learn.
https://www.owasp.org/index.php/OWASP_Mobile_Security_Testing_Guide
https://github.com/OWASP/owasp-masvs