www/content/datengarten/105.md

1.3 KiB

categories tags series title no subtitle speaker date event location language streaming recording
Datengarten
emergency
apps
itsecurity
Datengarten Datengarten 105 105 IT-Security Weaknesses of Emergency Alert Apps Malte Schoenefeld, Marc Schoenefeld 2019-12-04T16:23:00+02:00
start end
2019-12-10T20:00:00+02:00 2019-12-10T21:00:00+02:00
CCCB en false https://media.ccc.de/v/dg-105

Emergency Apps (like NINA/DE, FEMA/US and others) are a novel approach to enhance conventioal emergency alert channels with mobile devices, which nowadays are owned by the majority of the population to connect them to omnipresent data sources of the Internet. Due to typical characteristics implied by the design of mobile operating systems and applications, emergency apps on the hand have short version life cycles, on the other hand should be resilient to human and technical failure. Therefore we present the features of mobile apps, describe typical requirements towards these. To provide a practical result we scanned several apps for typical vulnerability patterns (and placed these in the CVE/CWE categories). In the end we summarize our research results towards a wish list to promote standard infrastructure and quality criteria for the development and deployment of such apps.