WS: SECURE COMMUNICATIONS IN ANDROID WITH TLS/SSL

DEF CON 25

Presented by: Miguel Guirao
Date: Saturday July 29, 2017
Time: 14:00 - 16:00
Location: Florentine Ballroom 3
Track: Crypto and Privacy Village

Secure Communications in Android is an introductory talk into the amazing cryptographic technology ofOpenSSL, that has helped us to achieve what the Internet is today, and the tasks we can perform on it. OpenSSL as become since many years ago, thedefacto library/tool for implementing cryptographic protocols into our applications and secure them. Of course, this task is not that easy as it sounds, in order to achieve a secure communication in our applications, we not only have to choose the more secure library, but also, have the knowledge to implement it in a secure manner and more.

This talk aims to teachyou the basics of the world of criptography, then an introduction to theimplementation of OpenSSL in Android, then three coding labs in Android inorder to learn how to integrate the OpenSSL library and implement the cryptographic protocols into your own applications.

You will learn to: Whatis Cryptography and it's basics What is OpenSSL and what it is used for The Android implementation of OpenSSL Coding Lab 1: Creating Secure Sockets (SSL/TLS sockets) Coding Lab 2: Working with Certificates Coding Lab 3:Working with Message Digest Coding Lab 4: Implementing a Client-Server Secure Communication

Miguel Guirao

Miguel Guirao (aka Chicolinux), as been in theinformation security industry for around ten years, he is a freelance consultant at Futura - Open Solutions, where he also has been training professionals about Linux Management, Information Security and Programming. Hehas been also a professor since 2009 for the Anahuac Mayab University where he teaches at the School of CS Engineering and at the School of Multimedia Design. He teaches Information Security in the Master of InformationTechnology Management. He holds a GCIH Certification from SANS. He is a SANS Mentor. This is the second time that Miguel participates at DEFCON,last year at DC24 he taught INTRO TO MEMORY FORENSICS WITH VOLATILITY workshop. Twitter handle of presenter(s): @miguelguirao


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats