The security issue that killed a financial product launch

A presentation at Agile Testing Days 2018 in November 2018 in Potsdam, Germany by nicola sedgwick

Slide 1

Slide 1

the security issue that killed a financial product launch (that was missed by the professional penetration testers and security ‘experts’)

Slide 2

Slide 2

https://www.agiletestingdays.com https://twitter.com/nicolasedgwick http://www.nicola-sedgwick.com

Slide 3

Slide 3

crowd

Photo credit Rob Curran on Unsplash

Slide 4

Slide 4

crowd - bounty.

Image credit https://internetbugbounty.org/

Slide 5

Slide 5

crowd - reward

Photo credit Christian Dubovan on Unsplash

Slide 6

Slide 6

crowd - professionals

Photo credit Hello I'm Nik on Unsplash

Slide 7

Slide 7

story

Photo credit Sharon McCutcheon on Unsplash

Slide 8

Slide 8

story - ethics

Photo credit Cristian Newman on Unsplash

Slide 9

Slide 9

story - vulnerable

Photo credit Mihály Köles on Unsplash

Slide 10

Slide 10

challenge

Photo credit Luke van Zyl on Unsplash

Slide 11

Slide 11

challenge - shopping

Photo credit rawpixel on Unsplash

Slide 12

Slide 12

challenge - practicalities

Photo credit Fancycrave on Unsplash

Slide 13

Slide 13

challenge - reputation

Photo credit Jon Tyson on Unsplash

Slide 14

Slide 14

challenge - competition

Photo credit Patryk Sobczak on Unsplash

Slide 15

Slide 15

situation

Photo credit Matt Botsford on Unsplash

Slide 16

Slide 16

situation - owasp

credit https://www.owasp.org

Slide 17

Slide 17

situation - tools

Photo credit Adam Sherez on Unsplash

Slide 18

Slide 18

situation - understanding

Photo credit John Carlisle on Unsplash

Slide 19

Slide 19

analysis

Photo credit Luke van Zyl on Unsplash

Slide 20

Slide 20

analysis - protested

Photo credit Robert Hickerson on Unsp

Slide 21

Slide 21

analysis - impenetrable

Photo credit Ben Hershey on Unsplash

Slide 22

Slide 22

analysis - landscape

Photo credit Luo Lei on Unsplash

Slide 23

Slide 23

analysis - maze

Photo credit Wim Arys on Unsplash

Slide 24

Slide 24

analysis - sense

Photo credit Vladislav Klapin on Unspla

Slide 25

Slide 25

hacking

Photo credit Markus Spiske on Unsplash

Slide 26

Slide 26

hacking - vulnerability

Photo credit Hans-Peter Gauster on Unsplash

Slide 27

Slide 27

hacking - system

Photo credit rawpixel on Unsplash

Slide 28

Slide 28

hacking - transmission

Photo credit Jack Price-Burns on Unsplash

Slide 29

Slide 29

hacking - breach

Photo credit Ben Hershey on Unsplash

Slide 30

Slide 30

disbelief

Photo credit Jonathan Hoxmark on Unsplash

Slide 31

Slide 31

disbelief - halt

Photo credit Kai Pilger on Unsplash

Slide 32

Slide 32

disbelief - denied

Photo credit B J on Unsplash

Slide 33

Slide 33

disbelief - perhaps

Photo credit Mike Wilson on Unsplash

Slide 34

Slide 34

repetition

Photo credit Tine Ivanič on Unsplash

Slide 35

Slide 35

repetition - footsteps

Photo credit eberhard grossgasteiger o

Slide 36

Slide 36

repetition - payments

Photo credit Ales Nesetril on Unsplash

Slide 37

Slide 37

advice

Photo credit Melinda Gimpel on Unsplash

Slide 38

Slide 38

advice - trouble

Photo credit Ye Jinghan on Unsplash

Slide 39

Slide 39

advice - gifts

Photo credit freestocks.org on Unsplash

Slide 40

Slide 40

realisation

Photo credit Jez Timms on Unsplash

Slide 41

Slide 41

realisation - broken

Photo credit Stephanie Watters Flores on Unsplash

Slide 42

Slide 42

outcome

Photo credit Taskin Ashiq on Unsplash

Slide 43

Slide 43

outcome - bounty

Photo credit Brian Mann on Unsplash

Slide 44

Slide 44

summary

  1. this is not an isolated situation
  2. tools assist testing; tools don’t test
  3. think critically during design
  4. always return to the beginning

Slide 45

Slide 45

takeaways

• You already have the skill you need to find security issues … your brain! • Critical thinking skills are perfect for locating security problems. • Engage security assessment as part of architecture planning and throughout development. www.agiletestingdays.com |

A g i l eT D

nicolasedgwick | www.nicola-sedgwick.com

Slide 46

Slide 46

https://www.agiletestingdays.com