Listen

Description

Upwardly Mobile

Episode Title: The Good, The Bad, and The Ugly in Mobile Encryption

In this episode of Upwardly Mobile, hosted by George & Skye and sponsored by Approov, we dive deep into the crucial world of encryption algorithms for mobile app developers. Protecting user data is paramount for trust, compliance, and preventing breaches, but navigating the landscape of encryption can be challenging. We break down algorithms into three categories: The Good, The Bad, and The Ugly, discussing which ones to use, which to avoid, and learning from past failures.Episode Summary:Encryption is non-negotiable in mobile development, affecting data security, privacy, and compliance. Choosing the right algorithm is critical, as not all are created equal.The Good: We highlight modern, reliable encryption algorithms essential for mobile applications.

The Bad: Certain algorithms are outdated, inefficient, or have known vulnerabilities and should be avoided at all costs.The Ugly: Some cryptographic failures stem from inherent flaws, flawed implementations, or real-world exploits.The Future: Post-Quantum Cryptography (PQC): With the potential advent of large-scale quantum computers, current public-key algorithms like RSA and ECC may become vulnerable.Key Takeaways: Prioritise strong, efficient, and widely-supported standards like AES-256 and ECC. Phase out vulnerable algorithms like DES, 3DES, and RC4. Avoid disastrous failures like MD5 and WEP. Use secure protocols like TLS 1.3. Manage keys securely using platform features. Learn from the 'Ugly' examples and avoid implementation pitfalls. Stay informed about post-quantum encryption to prepare for the future.

Keywords: mobile app security, encryption algorithms, AES, ECC, ChaCha20-Poly1305, TLS 1.3, SHA-2, SHA-3, Argon2, bcrypt, DES, 3DES, RC4, MD5, SHA-1, WEP, PQC, Post-Quantum Cryptography, CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+, HQC, app attestation, API protection, mobile development, cybersecurity, data security, cryptography.

Learn more about the sponsor, Approov: https://approov.io/