Mobile

Full list of my blog posts, publications and talks in category mobile.
Filter by
blurry image for loading
blurry image for loading
security
Survey: most people don't lock their android phones - but should
Survey: most people don't lock their android phones - but should
Blog post Mar 2014
Half of Android users don’t bother to lock their phones, despite having the choice of using patterns, passwords, PINs, and even their faces to secure their devices. This contrasts starkly with a report from the Federal Communications Commission warning that up to 40 percent of robberies in major cities involve cell phones. More precisely, over 52 percent.
blurry image for loading
blurry image for loading
user experience
Phone screen size: bigger isn't always better
Phone screen size: bigger isn't always better
Blog post Jan 2014
Marketers agree: screen size is a top priority for anyone shopping for their next cell phone but my new consumer survey challenges this conventional wisdom.
blurry image for loading
blurry image for loading
web
The (untold) price of doing local search
The (untold) price of doing local search
Blog post Sep 2013
Nearly everyone loves mobile apps that can perform local searches, get directions, or find the nearest decent restaurant. But what’s not so obvious is that these local apps can have hidden bandwidth costs — meaning that, in some cases, they can run up your phone bill in ways you might not expect.
blurry image for loading
blurry image for loading
web security
Apple finally turns HTTPS on for the app store, fixing a lot of vulnerabilities
Apple finally turns HTTPS on for the app store, fixing a lot of vulnerabilities
Blog post Mar 2013
Early July 2012, I reported to Apple numerous vulnerabilities related to their App Store iOS app. Last week Apple finally issued a fix for it and turned on HTTPS for the App Store. I am really happy that my spare-time work pushed Apple to finally enabled HTTPS to protect users. This post discuss the vulnerabilities
blurry image for loading
blurry image for loading
web security
Sessionjuggler secure web login from an untrusted terminal using session hijacking
Sessionjuggler secure web login from an untrusted terminal using session hijacking
Publication WWW 2012
Session Juggler allows to log into any websites on an untrusted terminal on any modern browser by using a simple bookmarklet and a smartphone. The site credentials are never transmited to the untrusted. With Session Juggler users never enter their long term credential on the untrusted terminal. Instead, users log in to a web site using a smartphone app and then...
blurry image for loading
blurry image for loading
web security
Towards secure embedded web interfaces
Towards secure embedded web interfaces
Publication Usenix Security 2011
WebDroid the first framework specifically dedicated to build secure embedded WebApp. This framework is build on the insights we gleaned from the security analysis of 30 embedded devices web interfaces for which we found over than 50 vulnerabilities.
blurry image for loading
blurry image for loading
hacking
Framing attacks on smartphones and dumb routers: social sites tap-jacking and geo-localization attacks
Framing attacks on smartphones and dumb routers: social sites tap-jacking and geo-localization...
Publication WOOT 2010
We show that phone features makes Tap-jacking easier. We explain how to exploit router web interface to steal WiFi network WPA key and location. Finally we demonstrate how to exploit the frame scrolling attack to attack Facebook frame busting defense and leak private information from Yahoo mobile webmail.
--
Get cutting edge research directly in your inbox.