Securing the Mobile Frontier: Alan Snyder on NowSecure’s Mission
Alan Snyder, CEO of NowSecure shares insights on mobile app security, emphasizing the importance of DevSecOps, managing third-party risks, and pen testing. As mobile apps become vital for consumer engagement, ensuring their security is crucial. Regular pen testing, combining automation and manual checks, is necessary for compliance. Privacy risks are heightened with AI integration, and many apps mishandle user data. NowSecure aims to improve public access to app data and privacy features.
Transcript
Hey everyone. Welcome back here to another Tech Drunk TV interview. I am really happy to have this gentleman, actually, he reminded me he's been on our show in years past, way back in the r you know, in, uh, during our RSA DevSecOps events, which are, will be coming up this march.
It's early back to March this year. But let me introduce you to Alan Snyder. Uh, Alan, welcome to Tech Drug tv.
It's great to have you on. Thank you, Alan. It's great to be back.
Absolutely. Alan, you are the CEO of now secure. I should have said that upfront, but let me say it now.
Um, but you weren't born the CEO of now secure. Give us a little bit of your history, a little bit of your journey to taking the helmet now secure, Alan. Sure.
I'll give you the, the mobile app relevant, uh, pieces. Uh, it's, uh, frightening to say, but I've been doing a mobile app and mobile app security related, uh, companies for, uh, a little over 15 years. Started, uh, way back when I was a CEO of a company called Box Tone, where we did, started with Blackberry Management.
Then went through, actually it was very fortunate to be at the beginning of MDM with Apple, uh, and the start of that whole, uh, let's just say chaos, uh, in the market. And then we did, uh, iOS and Android management sold and exited to good technology, who then when they sold to, uh, uh, Blackberry, that was time for me to go do another startup. I, uh, ended up here at, uh, now Secure.
So I've been in and around the mobile and mobile app environment and ecosystem for quite some time. So have a deep, deep knowledge and understanding of the players, the tech, and it's been a wild ride and really fun to watch it evolve over time. Absolutely.
You've been doing mobile since there was mobile. Um, it's, you know, hearing some of those names, good technology. I was a customer.
Um, that, that's a blasts from the past. And of course the whole Apple MDM kind of fostered this whole idea of the walled garden and, and how we do these things and everything else. Um, and still dictates and still dictates many of the rules of the road of what you can and cannot do.
Yeah, it really does. And it's funny, right? Um, yeah, I remember back in those days talking to a friend of mine at Deutsche Bank, and this is, they first announced the iPhone and I was like, ah, I'm using a Windows phone.
It doesn't seem that much different. And he's like, no, it's gonna be all about the apps. It's gonna be all about the apps, and they're gonna have 10,000 apps.
And you know, I left. And here we are 20 something years later. Alan now secures a company that's been around the mobile app, mobile app security space for a long time, as you mentioned, geez, probably seven, eight years ago you guys were, were May, maybe even more.
You were, uh, sponsoring our RSA DevSecOps events. Yep. And, um, and here you are, here, we still are.
I think a lot of people out there, maybe you've heard of now secure. Some of them may in fact have a really good handle on now, secure, some not. But for those who are not familiar, how would you describe now secure to them?
Yeah, so our mission is to save the world from unsafe mobile apps. So, but a large, uh, aspirational mission. And we do it through really three use cases that, um, I would argue that virtually all, uh, enterprise organizations have and need to do.
And the first is DevSecOps. We were talking about they're building a mobile app. The mobile app is now 70% of the way their consumers or employees interact with the organization.
It's, uh, now almost over 50% of the way revenue flows through into an organization. So the mobile app is very, very critical. They wanna make sure that when they publish that app to the stores or you know, public or private, that it's secure before it gets there.
So DevSecOps, right? How do we go faster, better, faster, cheaper in terms of mobile app security? So DevSecOps is a big piece.
The next piece is third party risk. So there's a lot of apps that you didn't build, but you're putting PII you're putting intellectual property. It is collecting super sensitive data and has very important information in it, and you're running it and using it to conduct business.
So third party risk. How do you make sure those mobile apps are safe and secure? You know, so like if you're using, let's just say you're an enterprise and you're using Teams or Zoom, you didn't build teams or Zoom, but you're probably putting some pretty sensitive information in it.
Same thing with Slack. How do you know that you've taken reasonable care? Right?
So that's the third party risk piece. And then the last piece is, um, pen testing as a service. So the PTAS.
And that's 'cause there's a lot of regulatory requirements where many of our customers have to have a regular, uh, pen test. So our view is you want automation, be it first party or third party continuous automation. 'cause there's just too much change.
And we will talk about the data leaks and other issues as we get, uh, deeper into this. And then you want that manual oversight to go deeper to make sure that, you know, you've taken the attacker point of view and actually done a little, uh, offensive security to make sure that, you know, you really have things locked down. So we do, those are the three areas that we, uh, focus on for our customers.
Absolutely. And, and just before we jump into kind of today's topic of discussion, people want to get more information. You know, they, they got the good overview here from you, but they want to dive deeper.
What's their, what's their best kind of on-ramp? Uh, I would absolutely start at the now secure website. com.
Uh, there's a lot of information. Uh, we're very prolific in terms of, uh, again, with our mission to save the world phone, save mobile apps. We publish a lot of data around the safety, security, privacy, a lot of metrics and stats.
Uh, there's, uh, basically a breach tracker where we'll show you the list. 'cause a lot of times folks are like, oh, there hasn't been a mobile app breach like the SolarWinds. And we would argue, you're right, there hasn't been that we know of.
However, there is a continuous, uh, you know, paper cut of, you know, I would say two or three mobile app breaches, um, per month, uh, that are occurring. And those are the ones that we know about. And this is, to me, the big issue with mobile apps is that there just isn't sufficient telemetry.
There is a lot, lot of attack surface where people are sliding through that you never even know about. So when you look at it and go, gee, I wonder how they got in. I mean, we could talk about why I feel this way, but in my view, I know how they got in.
Mobile apps are a part of that, of how they got in when you don't know, how did they get into your backend systems. Mobile apps are gateway. They're being used.
Absolutely. And, and I think there's such a, uh, I know it's not the main topic today, but I, I gotta agree with you. There's such a, um, complacency around mobile apps, security by end users, right?
I, I like to think that the, the developers of these mobile apps are taking the time to really think about security and do something about it. But I think a lot of people, I think overall, you know, Alan, you and I have been around the bush a bunch of times, right? We used to take endpoint security really seriously, right?
Today, I would say endpoint security boils down to phishing. For most people. They're worried about being phished.
They're worried about clicking on something they shouldn't click. And, and rightfully so, that's how a lot of these attacks take place. But when it comes to our phones and the apps, and, and let's face it, you probably know better than me, the average person has what, 60, 70 apps on their phone or something?
Uh, 80, 80 apps. I'm ashamed to tell you I have closer to 120. But anyway, but you're Above up.
Yep. But you know, and that's just on the phone, not the iPad and some of my other mobile devices. But anyway, um, the average person doesn't just, I don't think they give it enough of a second thought as to just how big an attack surface that is out there.
A DX, That's true. I would argue it's an unfair fight to expect the average person to make to, to wage that battle and to get anywhere close to winning. They don't have the tools, they don't have the knowledge or skills.
This is where I look at it and say organizations need to do it from when they're building the app. So first party apps and on third party. So they need to do more to protect the consumer.
'cause I, it's just completely unfair to put this on the consumer to protect themselves. Now, I sincerely wish the consumer would raise a bit more of a ruckus with the developers around Why don't you do better privacy disclosures? Why don't you do a better job of managing, uh, and uh, handling data.
And again, we've got lots of stats that we could talk about, about what that means. Uh, but right now I believe that the burden of security and privacy falls squarely on the developers and the folks that are deploying these mobile apps into their environment. Um, so Absolutely.
Alright, I'll tell you again, maybe we could do this on another segment at some point. But one of my pet peeves is the repos. And, and there's the same thing, by the way, in software development, right?
Software supply chain security. Um, people download software from a marketplace, from an app store, from a repo. And, and they, and it's okay.
Yeah, it was up there. It must be real. And, and that's injected so much, you know, security for us.
What is the responsibility of the app store vendor of the marketplace vendor of the, of these repo maintainers. But anyway, all we'll save that one for, we Can do a whole segment on that. Now we've got the recent MPM issues are really good examples.
China mood. Do you know what's in your app? Do you know what's in your mobile app?
Uh, yep. You know, and there aren't many CVEs for mobile apps and mobile app components. They just don't exist.
So if you think that SEA is gonna save you, I would argue that you can run it and you'll love the results. But there's a lot that's false negatives. Absolutely.
And getting worse by the day. I might add. But anyway, but you know, we're gonna go to a dark place, Alan.
Let's keep it light and cheerful. Okay. Um, you guys recently had some, uh, uh, research work done.
Yes. Well, and we're, we're launching, uh, a privacy product, which is, so we did a lot of research into the needs and issues. 'cause when you really think about it, the mobile app is the best surveillance tool ever created.
And we all pay to have it, right? It knows where you are. It knows what you're doing.
It can track all sorts of things. Now, with the addition of ai, it gets even more powerful in terms of not just knowing where we are and what we're doing and our activity, but now we're gonna start, it's gonna start to understand the questions we're asking and how we're doing things. So to me, you put all this together, there is a real legitimate privacy risk for the enterprise in terms of their, uh, IP and the consumer in terms of their, uh, privacy data and what they're doing in thinking.
And so we, current, current tools, current methods, what most people are doing, right? Let's actually, we should talk about that before we dig in. But what's different, and the good news is this is all the easy to solve.
You just gotta actually do something to solve it with privacy. Privacy is such a hard problem. 'cause I need to see data in motion.
What most folks are doing is static source code analysis. Okay? Doesn't see data in motion.
I might catch a few privacy things, but I won't catch data in motion for sure. And I'm only doing it on first party code. For the most part, mobile apps are 70% third party components.
So did my static source get the entire mobile app? Pretty confident. The answer is it did not.
Mm-hmm. So it got some segment and it only got static analysis. So we would argue there's a gap just from the get go right there.
And it's twofold, right? You didn't see all the app and you didn't see data in motion. When we see with privacy is privacy is a multi-part problem.
It is a, what data is the app collecting? So permissions, where is it sending that data, right? How is it being used, right?
That gets a third party components. 'cause there's a lot of 'em. Um, and then was any of that activity understood and authorized?
And what I would say is, by and large, none of those three are answered by modern day, uh, enterprises for mobile apps. And that presents a gargantuan privacy risk for that. We just had an issue, uh, recently.
The, uh, new England Patriots, uh, settled a lawsuit. 1 million. A third party component was tracking geolocation That was not disclosed.
And again, maybe they knew it, maybe they didn't, right? It was settled. So we'll never know.
1 million. 'cause a third party, uh, component was tracking geolocation and it shouldn't have been, uh, for the users. And so that's a lot of risk.
And what we would argue is it is mostly a risk because a mobile app is the best surveillance tool ever created. And b, people don't know what their mobile apps are doing. They're not tracking and they're not watching.
And actually, I should say it clearly, the mobile apps are tracking is just the corporate and the enterprise and developers. They're not paying attention to what they're doing. And they're not paying attention.
'cause they don't have the tools, right? It's not, it's not like they said, man, I really want to build a insecure or, uh, leaky app today. Current methods just don't give them the visibility they need to be able to solve the problem.
Nope. Uh, I, I, again agree with you wholeheartedly. Um, wanna bring it back in though to some of this research, right?
You guys recently had a blog article up on the now secure blog with some of the key, uh, key findings. You know, you gotta, and I'm just reading from this so I apologize for just regurgitating, but, uh, in 50,000 apps that you tested in August alone, over 77% were found to contain common forms of, uh, personally identifiable information. BII, um, the third party components we, we spoke about, and I, I don't know if that's unique to mobile apps now, and I think that's the state of software today.
It's all third party components. I think 70 percent's on the low side, right? I I, I've seen, I've seen numbers higher to 80, 85%, uh, 98% of iOS apps have incomplete privacy manifests due to emissions relating to these third party components.
You know, the whole thing about SBOs is s is an SBOs part of the, you know, is it mobile app part of the SBO m uh, requirement as well? It absolutely is because it is a gateway into your organization. What's it?
It is the way consumer. So yes, it absolutely is. And the, the, the, I wanna talk a little bit about the manifest piece because this to me is a real risk for, uh, companies.
'cause in essence, so I'll describe a little bit more about what we're saying. Both Apple and Google have requirements for the app developer when you submit to the stores to attest itself, attestation. So to attest to what data your apps collects and how it's used.
So that's public. You can go look at the, the, the play store and the, uh, iOS app store and you can, you, the consumer or the enterprise can see that data. What we're telling you is they're wrong.
The vast, I mean, 98% of the time those attestations are wrong. And again, I don't think it's because the company said, man, I really want to go and, uh, misrepresent the facts about what my apps are doing. I think it's because they just don't have the visibility they need to get it right.
And it's really hard. Now that does a disservice to the consumer. It is a embarrassment risk to the company, right?
Because alls it takes is one good security researcher or I don't know, someone like now secure who actually has automated analysis and could actually tell you to start to say, this app says it does this, but it actually does. You know that maybe more, right? Because very rarely does it, Hey, I said I do this and I don't do it.
It's like they do it and then they do 12 things beyond that. And so those are real risks for the consumer, real risk for the enterprise that they just, well, that's how you end up with something like the New England Patriots and a lawsuit, which is, I I don't believe that this is malicious, right? I don't believe that this is, they intend, uh, to do harm.
But I'd also say all that noise allows the apps that actually are malicious to hide in the noise. Yep. No, on that note, let, so as a Pittsburgh Steelers fan, I find it hard to have any sympathy for the New England Patriots.
But, but that being said, I'll relate it to stuff here at text. We, we had recently received a notice about, again, some data broker tool or something on, on one of our sites. And I had, I, it didn't, and I, I'm pretty hands on, you know, technically I've been in the tech business a long time, pretty hands on.
And I, I said, I don't recognize this. Where the heck is it? Where is it?
You know, where is it? And I had our, I-Team, team, you know, do a dive. We didn't preliminarily know.
We, we don't, no one knew what this was, but it was a third party tool that was using this. And so it it, you know, by, by just interjection it, it winds up in the manifest there. And yeah, and I was horrified to tell you the truth, that, you know, I, I felt like I was asleep at the wheel, if you will, that I didn't see this or even think about testing for this kind of, you know, uh, I mean it's classic, right?
You, you have a third party vendor and you don't test what they're using or what they're doing or you don't know what they're using and it, and it, and it comes back to you. Um, it, It's, well this is where dynamic testing is critical because, and back to your s bomb piece, transitive dependencies. So now I've got dependencies of dependencies of dependencies.
The only way to really understand that is put the data in motion and see and exercise the app and see where is your data going. What are all the endpoints? Did you know about it?
Did you authorize it or not? Right? So we look at all the tracking demands, we look at all of those endpoints, we understand all that.
So we can give you that complete list because that's the only way you can effectively do privacy, which is to say, I know everything that my app is doing 'cause I've exercised it and I've seen it. Those transited dependencies are a real challenge, uh, certainly for static analysis. I would argue they're a challenge for dynamic analysis.
Well, but when you run the app, we're going to see the data flowing and we're gonna go back and say, Hey, here's all the tracking domains we you saw. Here's all the endpoints we saw. And then the customer could say, I did or did not agree to.
Uh, that, and you can also see what data went to it. Because a lot of times we see over collection, which is, you said I wanted to use it for these two, uh, pieces of data, but instead it's taking 10, wait a minute, I didn't say you could take contacts. I didn't say you could track geolocation.
I didn't say you could do it in the background, right? Those sorts of things. But the answer is, well, you kind of did.
'cause you put the component in and then you didn't control it and lock it down and manage it. And when the component overreached, guess what? You just overreached.
You just didn't know it. Fair, fair enough. Um, Alan, for people who want to get more information on, on this, uh, research and some of the key findings, I mentioned the blog article.
Is that the best place? Can they get the whole, is there a report on it that they could download? The blog article is definitely the best place.
We'll go in and, and give the data. And in fact, we're gonna be, um, uh, launching some items as well where we're gonna make some of this, uh, public, right? And what we're going to, when I mean some of this we're gonna make public is we're gonna start to show here's what we see as, um, the apps doing publicly.
So I wanna be super clear. Our goal is to say, Hey, these are the attributes that we see. The app is, does the app have dangerous permissions and what are they, what, uh, endpoints does the app send data to?
We are not gonna make a judgment call about the risk of the app. And the reason is we don't want to be, uh, let's just say making an attacker's job easier by saying this app can or cannot be attacked. So we're gonna start to, you know, we're gonna go halfway, right?
We're gonna show, uh, let's just say the, we're gonna show actual factual attributes of the app so that somebody could draw their own conclusions about what that app is doing, uh, to actually get the risk indicators for the app. That's where, okay, we're gonna, we need the vet and understand the customer and who you are to make sure that that data is, is appropriate, uh, particularly on the third party risk. But we're gonna start to make some of this more publicly available to make it easier.
'cause that's a big problem today, which is there's not a good way to go and know unless you've got your PhD in mobile app security, which most people don't. Um, good news now secure does. So we're gonna make that a lot easier for folks to understand.
And, um, no, no pressure. But what, Uh, you're gonna see that over the course of the, uh, so part of it's gonna launch, uh, this week in terms of the privacy and the blog and everything, and then the, uh, other pieces will be over the course of the next two weeks as we get the, uh, oh Really? That, that nda.
Okay, very good. Mm-hmm. Excellent.
So, you know, keep an eye on that. The, the, the, the, the privacy, I don't wanna call it the app, but the privacy functionality and everything you spoke about that will be available by the time people won. You know, we record these videos, it'll be out in three days or so and around that, Yes, that, and that's in the core now secure product and analysis.
And the whole idea there is when your app behavior doesn't match what you've attested to in the public stores, we'll alert you and tell you you've got a reconciliation issue that needs to go and be addressed. Um, let's take ai, right? Right now, how do you know if AI's in your mobile app, right?
Because again, back to those 70% components, do you really think that those, uh, open source components and those closed source components are not gonna add ai? Of course they are, right? You're gonna end up with, you know, 15 different ais in your, uh, mobile app, right?
For all the components. We actually will go through and give you that asset inventory and list and then tell you what data and how it's being used in those so that you can go through and say, authorize, authorize, well, it was authorized, but not for that much data. Only for this data.
So you can make good governance decisions around how your data is being used. Love it. Excellent.
Hey Alan, unfortunately we we're outta time here. Uh, we mentioned the website. Yes.
com is the place to go, has everything you need in terms of the products first party risk, third party risk, all our DevSecOps and all of this research. Go look at the blogs, uh, it, great, great data. And our goal, the nice thing about this is it is really easy to solve.
You just need to take an action to solve it. Status quo, static source code analysis. Not enough, nothing wrong with it, it's just not enough to solve the challenge.
It's a fine beginning. Um, Alan, thank you for, it was good re reconnecting. Hopefully we'll talk before RSA, but if not, we'll we'll definitely see you at RSA, right?
Um, keep up the great work at Now Secure. com. But we're gonna take a break here on Tech Trunk tv.
We'll be back in just a moment.