René Mayrhofer
René Mayrhofer
Home
Publications
Presentations
Posts
Courses
Projects archive
Contact
Light
Dark
Automatic
Android
Android Security: Taming the Complex Ecosystem
The Android ecosystem is immense, represents a diverse manifold of use cases and participants, and is therefore highly complex. At the …
2019-05-15 09:15 — 10:15
Miami, FL, USA
Slides
Android security trade-offs 1: Root access
Android security trade-offs: Rooting “Rooting” has been part of the Android ecosystem pretty much since its creation. Within the context of this blog post, I define rooting as a method to disable standard sandboxing mechanisms for particular processes, which is a superset of Nick Kralevich’s earlier definition because many posts mix up the intentional, user-driven root access with exploitation of vulnerabilities.
René Mayrhofer
Last updated on 2023-05-16
7 min read
Android security trade-offs 0: Ecosystem complexity
Android security trade-offs The Android ecosystem is highly diverse, complex, and has many different stakeholders typically not visible in the limelight. Consequently, making decisions about features in the platform itself — what we call AOSP (Android Open Source Project) — is hard, and often in surprising ways.
René Mayrhofer
Last updated on 2023-05-16
6 min read
Insider Attack Resistance in the Android Ecosystem
The threat model for a mobile device ecosystem is complex. In addition to the obvious physical attacks on lost or stolen devices and …
2019-01-29 16:30 — 17:00
Burlingame, CA, USA
Slides
Video
Android-IPv6Config
[Finished] Enabling IPv6 address privacy on Android devices.
Josef Ressel Center u'smile
[Finished Sept. 2017] Research Center for User-friendly Secure Mobile Environments
Malware report for appjolt.com
Executive summary appjolt.com is seemingly an iOS and Android library/SDK to bundle with other apps. It is a special form of malware typically referred to as spyware, and is even worse than the typical advertiser network libraries that include in-app advertisments during use.
Last updated on 2019-12-21
15 min read
Android Exploit Framework
[Finished] Android on-device permanent root exploit framework
IPsec/L2TP gateway for Android and iPhone clients on OpenWRT
How to set up an OpenWRT router/gateway as an IPsec/L2TP gateway for Andoid and iPhone clients The only “reasonable” (that is, not counting PPTP due to its known security issues) VPN protocol supported by default on non-rooted / non-jailbroken Android / iPhone phones as clients is the combination of IPsec and L2TP.
Last updated on 2019-03-24
7 min read
Private Notes
[Finished] Cross-platform end-to-end encrypted note-taking app
«
»
Cite
×