Bit.ly is not in Lybia

When deploying (mobile) apps for verticals such as Healthcare or Banking, you typically have to get the app approved or blessed by the customer’s IT security team. Some tips or info: Only deploy, even for Proof of Concepts (POCs), properly signed apps Do not use or store personal identifiable information that can track users Use … Read more

On Location (and Other Sensitive) Data

Installing apps, Android in this case, is at times a bit of WTF. It shouldn’t have to, but it is. The amount of personal information that some apps gather can be extreme. This concern is especially true after Google removed the very necessary App Ops (permission manager) app. Let me provide an example. An app … Read more

Android App Ops is a Step Forward

Update Dec/15/2013: Two weeks after I wrote this piece below, Google removed App Ops… See Android App Ops *WAS* a Step Forward, and stay tuned. One of Android’s top limitations, one that totally drives me nuts, is its security model, in particular the app permissions model. This is a permission security model where developers (the … Read more

Security & Privacy on Mobile Apps, Part 3 – PCI Compliance

This is Part 3 of a series on Security & Privacy for Mobile Apps. Part 1 of this series introduced main concepts related to security on mobile apps. Part 2 went deeper into the security elements and guidelines related to security and privacy on mobile applications. In this Part 3, I will cover security from … Read more

Article: Understanding security on Android

“When you develop Android applications, you must deal with a number of security-related aspects, including application processes and sandboxes, code and data sharing, system protection through application signing, and permissions use.” See my article Understanding security on Android (IBM developerWorks) which introduces the different aspects of security on Android. ceo

The BlackBerry Ban Debacle and General Implications

And the world has suddenly gone paranoid and/or Big-Brother with RIM: In the UAE where “The issue … against BlackBerry’s super-secure encrypted services” (Reuters); In India where “Indian officials say they need to be able to intercept BlackBerry messages” (Information Week); In Indonesia where “We don’t know whether data being sent through BlackBerrys can be … Read more