Daniel Shugrue, Digital.ai | RSA Conference 2023
The Organization of Web App Security Professionals (OWASP) recently updated their Mobile App Sec Verification Standard (MASVS). In this interview with Daniel Shugrue, security evangelist at Digital.ai, we discuss how your DevSecOps practice can help your apps meet the “Resiliency” recommendations from the OWASP MASVS. Particularly, we discuss how anti-tamper techniques require special attention in your CI/CD process.
Transcript
This is texturung TV. Hey everyone, we're back here. We're streaming live.
It's probably close to noon for all my friends back on the East Coast through the us later in the afternoon. If you're in Europe, this might even be the middle of the night for our friends in India in Australia and Singaporean wherever you are in the world welcome. We're live at the RSA conference here in mosconee.
Along with 40,000 some odd of our friends. We're happy to have you join us. We'll be covering we started our coverage yesterday.
We'll be here all week with lots of interviews and information and news about what's going on. I don't with as they say on the state on the science where the world comes. To meet security.
My next guest is Dan Shigeru. Dan is with digital AI. He has an interesting history though in security.
We're gonna ask him to talk about it Dan. Welcome to techstar TV. Thanks for having me.
Great to be here. Absolutely. So Dan, why don't we start with a little bit of Europe, you know kind of personal Journey sure.
Sorry. Yeah, so I started out in the world of mobile at Nokia way back in the day and I've been from there went to RSA the company as opposed to the conference with did my time at Akamai which with Andy Ellis who was just here. Yeah and my Mafia out there then did some time in some Israeli startups.
Okay, both of which exited successfully the last one was bought by Microsoft where I spent a little over a year doing confidential Computing. Wow, ton of fun. And then for the last couple of years, I've been at digital AI.
I love it. That's a great that's a great resume and interesting Journey, right? It's been a lot of that that's part of the security experience.
If you if you're working on the vendor side of things, right? Yeah you tend, you know companies get bought companies. Holding you tend to do things like that.
Yeah and get to spend a lot of time in Israel, which is fun. If you're in cyber security. There's a good chance.
You're spending some time in Israel. Yes, right outside those 8600 headquarters where they I think they find people up. It's like they're coming out the door.
Yeah sign them up. Yeah before there was a draft. com and we are Security Boulevard.
It's not a stranger. Yeah, there's gonna be people out here. I'm sure who are watching this today who are not familiar with that.
I it's a fairly sure. It's a fairly new brand. i is a conglomeration of five different companies most of which were in the devops space.
So we have an agility arm, which was just bought in 2020. We have a release and deploy piece which used to be zebia Labs. Sure AI component which is a verified based right out here in San Fran and then security which is used to be called ark sand Technologies which provides the obfuscation Paul's the resiliency and absolutely part of there's a big value stream component.
Yes narrated from was it not Network one something with the word one version one. Yes. Yeah.
That's the agility piece. Yeah, exactly. Yes, and that's a big piece of it too and really look I mean, I remember when they launched digital AI the idea here.
us to put together a Soup To Nuts and end to end solution For the devops life cycle for the software development life cycle. And of course, you can't do that without including security. Right?
Right. Yeah, and that's why you know, the security piece of this is so important so important. Yep.
Just before we jump into the rest of it for people want to get information. ai Digital Dot AI. Yep on the web.
Yep. Just want to put that out there. So Dan, you mentioned a lot.
Yeah, a lot of us think of, you know, we know who all was obviously, right? And the first thing you think of is oh, what's top 20? There's a way for what's nice to see everybody here.
People are back. Yeah, right. So you think about the owass top 20 and what that means and but oh watch does more today than the top 20, they recently recently.
Not that recently but release the old west API security left. We're here to talk about it yet another yeah release from our lives. Yeah, the mobile application security verification standard.
So it's this part of the mobile application working group, which is a part of os which is almost I think almost 10 years and I think it's more. Yeah, so the apps that piece is is big and updating because mobile apps are big. Yeah and Olaf decided that you know application security for mobile is it's a different beast from web application security.
And so they have something called a verification standard or the Mobile application security verification standard nasvs and they just released. 0. So a big Point release for the new verification standard.
Yep, and it is yeah. So what do you think the higher if you don't mind sure give us some of the highlights of the release. So what what they have done is they've adhered more closely to the nest standard and the nest way of describing things because nist has for their part made known that they are going to be using owasp as the de facto standard for mobile app SEC really which is great.
Yeah the organization so they've they're adhering more closely to that. ai is most interested in which is resiliency. Otherwise known as pardoning sometimes called shielding.
They've they're they Reduced the number of requirements from roughly eight or nine down to four meaning that the umbrella basically got bigger for each of those four and I think ultimately that's going to make it easier for people that aren't that well versed in what resiliency is to understand it. So that's a good thing. Yeah, and then and you know, it'll also make it a little bit easier to test to make sure that applications are meeting those standards because it's basically, you know, it's four check boxes instead of one.
And so yeah, so that's a it's a it's a good thing in terms of bringing more people into the fold making the standard more understandable and which is important because there's not a you know within the world that we're in everybody understands all the big banks are doing something to harden their apps. The gaming companies are doing that. The media streaming companies are doing it whether it's for DRM or to protect.
Well IP and and even just to protect I guess it's DRM in the end but anti-piracy. and so But outside of the world about application hardening, there's not a ton of understanding of what resiliency is or whatever right? And there really is and you what's funny is You know the whole idea of resiliency resilience.
Is really something that's it's it's so quarter security or should be. Yeah, right and and we and I do see it used more and more right I've seen training around. Resiliency and stuff, but it's something that needs.
Yeah, better better brought home better. Yes. Yeah.
Yeah, I mean so the idea is you know with with mobile apps that once a company makes an app publicly available. Meaning they've got it in the App Store. They've got on the Play Store they really, you know by definition they have no control over who's downloading it and and you know, they it's to their advantage to have as many people download it as possible.
Of course. That's the idea. Yeah.
So exactly that's the idea. So you're talking about you know, whether it's a bank or gaming company. If it's a popular bank or a gaming company or even a medical device company, we're talking about tens of millions of downloads.
1% you know, you're talking about hundreds of thousands of people who are going to try to do something with that app. And once they downloaded it it's in their own environments and it's outside of the control of the company that's made it. So a threat actor or just a curious user.
We'll put it on a jailbroken phone. We'll put it on a rooted phone. They might put it in an emulator and empty bugger or you know, sort of work.
They're gonna try to reverse engineer. Yeah. I mean, that's the bottom line.
So yeah good and a lot of people Look, probably not as many of our security friends, but a lot of people I think say. Oh, no, you know that what would exists on my phone is really just a front end and every all the good stuff is up in the cloud, you know that mystical place and they can't get to that. But you know, they can't they can yeah, and there are apis.
It's a roadway into it. Yep. That's it's exactly there's and there's a blueprints really in that app to show.
How do you get to the back? Yeah. I know.
Once the app is reverse engineered with red African. Look at that and say oh, okay. There's where the call is.
Here's the type of string that it's expecting. How can I manipulate that in order to get in myself, you know didn't over the years. I've been insecurity a long time as you have right it was so funny because at one time Right.
There was a distinct mobile application track, right my friends. It's a now secure. Yeah, they were big on mobile security.
There was another one in Israeli company that was acquired by Perfect. Yeah. Yeah.
That was no this one was the Perfecto mobile. Okay. Yeah.
That was them you had a lot of just dedicated mobile security companies. You don't see them as much because I think mobile has been. Integrated we've been assimilated right by the Borg of security and and but in doing so it kind of lost its identity.
Yeah. Yeah. I mean sorry, I think this old wash things really important.
Yeah. Yeah. I mean there is a need for mobile specific security.
I mean part of the challenge or it could even be seen as an advantages, you know, some of these applications are written in JavaScript. So they really are hybrid. I mean they can serve both as mobile apps where they can serve as the front end or the client side of a web in which case, you know, there's a specific type of application that you're doing for them and then you know and not but and then in the case of Apple, you're writing specifically for iOS you're writing in Swift and then you need a very specific set of tools.
Absolutely. It's still a different animal. Yeah.
Yeah, no matter how much we may say yes, not security security. Yeah. It's a different environment with a different set of risk or the different set.
Of solutions. Yeah, I mean, you know and in the end whether it's desktop or a web client or client side of a web app or mobile. The commonality is that the app is outside of the app makers control.
Outside the firewall and thus you know, how do you monitor it? How do you ensure that if it's reverse engineered? ai.
I got it. All right, Dan. We said mentioned digitally i i people who are at the show you guys are over on the show floor.
We are indeed. Yeah, go check them out there booth number 54 24. Yep, 54 20.
It's a huge show floor man. It's a big one. Yeah, that's why they feel like we're back this year.
Oh, no, there's no doubt. We're back. Yeah, we're back and it's fun to be back.
Yeah. All right. We're gonna take a break here.
We've got Dan I messed up your last name. a. I will have another guest in a minute.
We're live at masconi stay tuned.





