the future of secure, mobile authentication

13
Mobile Security and 2FA The reality from the trenchesOllie Whitehouse, Associate Director, NCC Group

Upload: derektop

Post on 19-Jun-2015

197 views

Category:

Technology


2 download

DESCRIPTION

From Voice Biometrics Conference San Francisco (May 8-9, 2013): Mobile devices have the potential to be the universal device to make authentication stronger. But a host of challenges stand in the way for mobile security platforms. What are the key enablers and how does voice fit into a comprehensive mobile security strategy? Ollie Whitehouse, Associate Director, NCC Group

TRANSCRIPT

Page 1: The Future of Secure, Mobile Authentication

Mobile Security and 2FA The reality from the trenches… Ollie Whitehouse, Associate Director, NCC Group

Page 2: The Future of Secure, Mobile Authentication

Before we begin…

• NCC = iSEC Partners in the USA • FTSE listed ~99 million GBP revenue • Independent security experts • Working in hardware, software and higher level business functions

• Trusted advisor to many • ~ 250 technical security consultants • ~ 80 business security consultants

Page 3: The Future of Secure, Mobile Authentication

Agenda for the 15 minute positioning..

• Mobile Security • Reality and Elephants • Future Enablers

• Authentication and mobile • 2FA – what it looks like today • Voice biometrics and its Role

Page 4: The Future of Secure, Mobile Authentication

Mobile Security – Security threats

• Hardware

• Platform • Android, iOS, Windows etc.

• Vendor Customisation • Undermining platform security

• Apps • Poorly designed / implemented

• User activity • Hygiene with regards to apps / jail breaking

Page 5: The Future of Secure, Mobile Authentication

Mobile Security – Challenges

• Mobile vendor fragmentation • Vendor spend on security • 18 to 24 month device life cycles • Carrier certification of updates • User awareness / education • User experience for security patches • Carrier / user desire for security patches

Page 6: The Future of Secure, Mobile Authentication

Mobile Security – Future

Page 7: The Future of Secure, Mobile Authentication

Mobile Security – Future

• The security arms race is starting.. • BlackBerry, Samsung, SEAndroid (Generic), Apple and Windows

• Platform features • TrustZone • Virtualisation / HyperVisors

• Software security •  Improving rapidly..

Page 8: The Future of Secure, Mobile Authentication

Mobile 2FA – Concerns

• Satisfying ‘Something you have’ • SMS latency

• The ‘NYE’ problem • The ‘malware’ issue

• For seeded / on-line • Jail breaking

• For seeded / on-line • Connectivity

• For on-line

Page 9: The Future of Secure, Mobile Authentication

Mobile 2FA – Drivers for mobile 2FA

Page 10: The Future of Secure, Mobile Authentication

Mobile 2FA – What we’re seeing

Page 11: The Future of Secure, Mobile Authentication

Mobile 2FA – Satisfying the concerns

• Today • Jail break detection • Device unique IDs • Device lockdown • Dual persona devices

• Tomorrow • TrustZone and friends

Page 12: The Future of Secure, Mobile Authentication

Mobile 2FA – Result (one solution seen)

Circuit Switch and Voice for Last Chance Fall-back

Page 13: The Future of Secure, Mobile Authentication

Mobile 2FA – Tomorrow?