EPISODE · Oct 10, 2017 · 23 MIN
Aditya Gupta -- The Exploitation of IoT
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why can an IoT product look secure in one component and still fail as a complete system? Aditya Gupta, founder of Attify, joins Chris and Robert at AppSec USA to examine the gaps between hardware, firmware, radio communications, mobile applications, and web dashboards. He explains how fragmented development teams and unfamiliar protocols create security blind spots, and why authentication and secure design need attention before devices ship. The conversation covers resource constraints, firmware updates, physical access, and the way extracting information from one device can enable attacks against many others. Aditya also discusses practical learning resources and encourages developers to understand their entire product architecture rather than assuming that securing individual pieces will secure the whole.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Aditya Gupta:→ Aditya Gupta and AttifyMentioned in this episode:→ Attify→ OWASP IoT Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The exploitation of IoT with Aditya Gupta00:46 Aditya’s path from mobile security to IoT02:03 Defining the Internet of Things02:58 Where IoT development goes wrong04:03 Security gaps between components and teams05:48 Authentication failures and secure design07:03 Practical security steps for developers07:58 Protocol fragmentation and resource constraints09:10 Designing the complete IoT system11:17 Updating devices after deployment17:30 How physical access exposes larger attack paths20:48 Resources for learning IoT security
Embed this episode
What this episode covers
Why can an IoT product look secure in one component and still fail as a complete system? Aditya Gupta, founder of Attify, joins Chris and Robert at AppSec USA to examine the gaps between hardware, firmware, radio communications, mobile applications, and web dashboards. He explains how fragmented development teams and unfamiliar protocols create security blind spots, and why authentication and secure design need attention before devices ship. The conversation covers resource constraints, firmw...
Ready to play
Aditya Gupta -- The Exploitation of IoT
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.