When Geo Goes Wrong - A Case Study of Geolocation Vulnerabilities in Mobile Apps

When Geo Goes Wrong - A Case Study of Geolocation Vulnerabilities in Mobile Apps

OWASP Foundation via YouTube Direct link

LOCATION SPOOFING can spoof your location as much as you want

19 of 27

19 of 27

LOCATION SPOOFING can spoof your location as much as you want

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

When Geo Goes Wrong - A Case Study of Geolocation Vulnerabilities in Mobile Apps

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 GEOLOCATION IN MOBILE APPS incorporating geolocation is the norm
  3. 3 How is GEOLOCATION ACCOMPLISHED (IOS)? using the Core Location Manager
  4. 4 GEOLOCATION (1)OS LEVEL PROTECTIONS os-level alerts
  5. 5 GEO CAN 'LEAK' IF THE APPLICATION IS BUGGY ...bad for users!
  6. 6 THEY KNOW YOUR LOCATION
  7. 7 COMMON CLASSES OF GEO BUGZ can compromise a user's physical location
  8. 8 INSECURE NETWORK COMMS
  9. 9 OVER PRECISE LOCATION
  10. 10 USER INTERFACE
  11. 11 EXAMPLE OF GEO BUGS buggy apps that compromised a user's physical location
  12. 12 STARBUCKS overpriced coffee, plus a shot of geo tracking
  13. 13 WHISPER the safest place on the internet - NOPE
  14. 14 TINDER precise geo of nearby users, allowed tracking
  15. 15 ANGRY BIRDS ... they are watching you play
  16. 16 GRINDR'S PREVIOUS ISSUES Those who cannot learn from history are doomed to repeat it
  17. 17 LACK OF SSL PINNING the app does not pin its certs
  18. 18 REPORTING OF PRECISE GEO
  19. 19 LOCATION SPOOFING can spoof your location as much as you want
  20. 20 WIDE-OPEN APIS unauthenticated, unlimited access to APIS
  21. 21 'BROKEN' UI LEVEL LOGIC what you see/say isn't what you get
  22. 22 DISCLAIMER our goal was to help Grindr under the issues
  23. 23 TRILATERATION determine absolute location from relative distances
  24. 24 USER LOCATION so lets map some users
  25. 25 IDENTIFYING USERS it'd be trivial to reveal anonymous user's identities
  26. 26 GRINDR RESPONSE foxes & current issues
  27. 27 QUESTIONS & ANSWERS feel free to contact us any time!

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.