Zum Hauptinhalt springen
🕵️ SicherheitslückenCVE-2022-44368 | NASM 2.16 null pointer dereference (EUVD-2022-47313)(18.09.2026 um 03:34 Uhr)
🔧 ProgrammierungBuilding a Browser-Based Voxel Editor with React Three Fiber(18.09.2026 um 03:24 Uhr)
🔧 ProgrammierungThe Bottleneck Moved From Writing Code to Proving It(18.09.2026 um 03:32 Uhr)
🕵️ SicherheitslückenCVE-2022-44368 | NASM 2.16 null pointer dereference (EUVD-2022-47313)(18.09.2026 um 03:34 Uhr)
🔧 ProgrammierungBuilding a Browser-Based Voxel Editor with React Three Fiber(18.09.2026 um 03:24 Uhr)
🔧 ProgrammierungThe Bottleneck Moved From Writing Code to Proving It(18.09.2026 um 03:32 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

SecTor 2025 | How a Mobile Drivers License App Became a Boarding Pass

Author: Black Hat - Bewertung: 2x - Views:21

It starts with a client and a late-night idea on a napkin. It turns into a SOC2-certified product trusted by Police, Government Agencies and the TSA.

You'll hear how we partnered with an ambitious state to augment their physical Driver's License with a new Digital ID built from the ground up. One that lets you access public services, legally buy age-restricted items and even board planes with just your phone.

In this 45-minute Briefing, you will walk away with:
- A blueprint for turning any 'idea on a napkin' into a certification-ready release.
- A pipeline template that performs security testing, triage, and pushes defects back to developer queues to ensure you don't go backwards.
- A threat-model approach that you can copy and use to quickly gain confidence with teams and customers.
- How to measure risk and establish an executive risk scorecard that gets to the finish line.
- Lessons learned from breaking and fixing facial-recognition, blockchain/SSI claims, and how to attack 3rd party verification apps.

Why does this matter? Unlike typical apps, failing here means anyone can forge an identity. With no mature framework to follow, we synchronised compliance, DevSecOps, and user-privacy across four orgs, three audit firms, and one very impatient legislature.

Key stories we'll unpack:
- What's going on with your data, and how an identity app works.
- Building a security-as-code pipeline that ships and keeps auditors happy.
- Breaking liveness detection and facial recognition implementations.
- When the ground shifts and new interoperability standards cause fraudulent verifications.
- How-to on achieving SOC2 certifications, encompassing everything from the mobile app to manufacturing plants.
- How to prove security to clients: threat modeling, pen tests, and 3rd party assurance.
- Integrating blockchain and self-sovereign identity.
- Successfully launching the final product with TSA approval for boarding flights.

If you've ever wondered how to 'secure it' when there are no roadmaps, no precedents, and the stakes are literally sky-high, this talk is for you. This session isn't just a story—it's a playbook for navigating the unknown, where security isn't just a requirement; it's the product.

By: John Duffy | Director - ID/Payment Security, Canadian Bank Note Company

https://blackhat.com/sector/2025/briefings/schedule/?#taking-a-product-from-napkin-to-soc2-certified--tsa-trusted-how-a-mobile-drivers-license-app-became-a-boarding-pass-47669

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SecTor 2025 | How a Mobile Drivers License App Became a Boarding Pass

Thematisch verwandte Begriffe: SecTor, 2025, Mobile, Drivers · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

↗ Original-Quelle