article thumbnail

Identify yourself for MIM - A Screw's Loose

A Screw's Loose

They may choose to do straight authentication against your enterprise id system, could use a certificate to do the same thing, or go with a token provided through oauth or SAML. ©2011-2012 A Screws Loose. Your developers look at the API and figure out what data matches the requirements they were given to build that app. Crapplications.

article thumbnail

The Cart before the Horse - A Screw's Loose

A Screw's Loose

They then map out how to authenticate the user. ©2011-2012 A Screws Loose. Due to this, they want to map the identity of the user reporting the expense and encrypt any data cached on the phone as well as allow offline access, since there may not always be coverage for the device. Crapplications. Enterprise Mobility. Expense management.

Mobile 56
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

The Hacker Mind Podcast: Hacking Healthcare

ForAllSecure

However, if somewhere along the supply chain, a bad actor has access to the package and can inject their malware into the system, then some huge problems can can occur. Vamosi: At Black Hat USA 2011, hacker Jay Radcliffe demonstrated before a live audience how he could hack his own personal insulin pump. Vamosi: This is bad.

article thumbnail

Barn Doors - A Screw's Loose

A Screw's Loose

Let’s build identification and authentication frameworks on which we can then base access to that data. ©2011-2012 A Screws Loose. We should be taking care of our data through its whole life cycle, you never really know where it’s going to end up or how it’s going to get there. Crapplications. Enterprise Mobility. Enterprise Strategy.

Mobile 60
article thumbnail

The Hacker Mind Podcast: Hacking Healthcare

ForAllSecure

However, if somewhere along the supply chain, a bad actor has access to the package and can inject their malware into the system, then some huge problems can can occur. Vamosi: At Black Hat USA 2011, hacker Jay Radcliffe demonstrated before a live audience how he could hack his own personal insulin pump. Vamosi: This is bad.

article thumbnail

The Hacker Mind Podcast: Hunting The Next Heartbleed

ForAllSecure

So on December 31, 2011, at almost midnight, a developer with direct access to OpenSSL, Robin Seggelmann, committed the change that changed the heartbeat function. And if you could initiate a heartbeat before authentication was complete on the site, you could smash and grab the encrypted information before anyone even knew who you were.

article thumbnail

The Hacker Mind Podcast: Hunting The Next Heartbleed

ForAllSecure

So on December 31, 2011, at almost midnight, a developer with direct access to OpenSSL, Robin Seggelmann, committed the change that changed the heartbeat function. And if you could initiate a heartbeat before authentication was complete on the site, you could smash and grab the encrypted information before anyone even knew who you were.