EPISODE · Mar 31, 2019 · 18 MIN
Georgia Weidman — Mobile, IoT, and Pen Testing
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A secure mobile application can still sit on a compromised device or depend on an insecure cloud service. Penetration tester and author Georgia Weidman joins Robert at CodeMash to explain why enterprise mobile and IoT security requires a wider view. She describes phishing through mobile channels, a QR-code demonstration that delivered a modified restaurant app, and the infrastructure behind connected devices. Georgia also discusses testing the protections vendors promise, learning the fundamentals through her book Penetration Testing, and the business lessons that came with becoming an entrepreneur. Her path from mathematics to security provides the backdrop for a practical conversation about examining the whole environment and understanding what an attacker can actually reach, rather than stopping at an individual app.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Georgia Weidman:→ Georgia Weidman on LinkedInMentioned in this episode:→ Penetration Testing: A Hands-On Introduction to Hacking→ CodeMashFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Mobile and IoT security with Georgia Weidman02:09 From mathematics to security03:33 The competition that sparked an interest in hacking05:28 Mobile and IoT in the enterprise06:37 Why mobile phishing matters07:45 A QR code and a modified restaurant app08:43 Looking beyond the app to the whole device10:10 Testing mobile security products and controls11:39 Learning with Penetration Testing13:43 Building a company and understanding business risk17:04 Conferences and international readers
Embed this episode
What this episode covers
A secure mobile application can still sit on a compromised device or depend on an insecure cloud service. Penetration tester and author Georgia Weidman joins Robert at CodeMash to explain why enterprise mobile and IoT security requires a wider view. She describes phishing through mobile channels, a QR-code demonstration that delivered a modified restaurant app, and the infrastructure behind connected devices. Georgia also discusses testing the protections vendors promise, learning the fundame...
Ready to play
Georgia Weidman — Mobile, IoT, and Pen Testing
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.