13
Mobile Security and 2FA The reality from the trenchesOllie Whitehouse, Associate Director, NCC Group

The Future of Secure, Mobile Authentication

Embed Size (px)

DESCRIPTION

From Voice Biometrics Conference San Francisco (May 8-9, 2013): Mobile devices have the potential to be the universal device to make authentication stronger. But a host of challenges stand in the way for mobile security platforms. What are the key enablers and how does voice fit into a comprehensive mobile security strategy? Ollie Whitehouse, Associate Director, NCC Group

Citation preview

Page 1: The Future of Secure, Mobile Authentication

Mobile Security and 2FA The reality from the trenches… Ollie Whitehouse, Associate Director, NCC Group

Page 2: The Future of Secure, Mobile Authentication

Before we begin…

• NCC = iSEC Partners in the USA • FTSE listed ~99 million GBP revenue • Independent security experts • Working in hardware, software and higher level business functions

• Trusted advisor to many • ~ 250 technical security consultants • ~ 80 business security consultants

Page 3: The Future of Secure, Mobile Authentication

Agenda for the 15 minute positioning..

• Mobile Security • Reality and Elephants • Future Enablers

• Authentication and mobile • 2FA – what it looks like today • Voice biometrics and its Role

Page 4: The Future of Secure, Mobile Authentication

Mobile Security – Security threats

• Hardware

• Platform • Android, iOS, Windows etc.

• Vendor Customisation • Undermining platform security

• Apps • Poorly designed / implemented

• User activity • Hygiene with regards to apps / jail breaking

Page 5: The Future of Secure, Mobile Authentication

Mobile Security – Challenges

• Mobile vendor fragmentation • Vendor spend on security • 18 to 24 month device life cycles • Carrier certification of updates • User awareness / education • User experience for security patches • Carrier / user desire for security patches

Page 6: The Future of Secure, Mobile Authentication

Mobile Security – Future

Page 7: The Future of Secure, Mobile Authentication

Mobile Security – Future

• The security arms race is starting.. • BlackBerry, Samsung, SEAndroid (Generic), Apple and Windows

• Platform features • TrustZone • Virtualisation / HyperVisors

• Software security •  Improving rapidly..

Page 8: The Future of Secure, Mobile Authentication

Mobile 2FA – Concerns

• Satisfying ‘Something you have’ • SMS latency

• The ‘NYE’ problem • The ‘malware’ issue

• For seeded / on-line • Jail breaking

• For seeded / on-line • Connectivity

• For on-line

Page 9: The Future of Secure, Mobile Authentication

Mobile 2FA – Drivers for mobile 2FA

Page 10: The Future of Secure, Mobile Authentication

Mobile 2FA – What we’re seeing

Page 11: The Future of Secure, Mobile Authentication

Mobile 2FA – Satisfying the concerns

• Today • Jail break detection • Device unique IDs • Device lockdown • Dual persona devices

• Tomorrow • TrustZone and friends

Page 12: The Future of Secure, Mobile Authentication

Mobile 2FA – Result (one solution seen)

Circuit Switch and Voice for Last Chance Fall-back

Page 13: The Future of Secure, Mobile Authentication

Mobile 2FA – Tomorrow?