Interviewing Security Researcher Filip Chytry
Most people tend to roll their eyes when the subject of online security is brought up – that is until they experience a problem with their device or system first-hand.
In our first Interview-the-Expert series, we’re happy to have Filip Chytry, Product Manager at Avast Software, maker of the most trusted antivirus in the world, protects nearly 230 million people, computers and mobile devices with its security applications.
Hi Filip, please tell us a bit about yourself. What is your background, and how did you get into the information security field?
I studied at a technical high school called Applied Cybernetics, where I worked on a selection of different fields of study including robotics, networks and programming. During these years, I was already curious about security and was becoming increasingly passionate about the industry, trying to learn more about cyber crime and attempting to hack into my classmates‘ computers for fun.
I then applied to the Czech Technical University in Prague and during the first two months of my studies, I started working at Avast Software as a malware analyst. Avast is where my security career truly began. Over the course of my first few years at the company, I experimented with working on a variety of programs; since then, my focus has gradually shifted towards the mobile sphere.
Most recently, I've been managing a project at Avast that develops new security features and have simultaneously started my project, Seculu.com, to help improve the security of both individuals and businesses alike.
Many people think that security is a dull topic. I cannot tell you how many “not again” kind of expression we received. So, what exactly do you find interesting about security?
Most people tend to roll their eyes when the subject of online security is brought up – that is until they experience a problem with their device or system first-hand. These days, people very much underestimate security risks and their potential consequences. Have you seen those rainbow tables with most commonly used passwords? From my personal experience, I can tell you that there’s still a large number of people who continue to use them.
What I find interesting is the development of these types of social behaviours – studying them is almost like observing an advanced level of programming. When examining the actions of others, you’re forced to think like a bad guy and always try to be one step ahead of the curve.
I heard that during your free time, you do a little bit of “hacking” on the side, of course, for good reasons. Can you share some of the findings? What do you want to know when you hack an application?
The sole purpose of what I refer to “security auditing“ is to improve the security of the app or the system in question. This especially applies to mobile apps I use, since it can be unsettling to know that your personal data isn‘t being handled securely.
Take popular social networks, for instance -- these sites share a significant amount of personal data, but most people are largely unaware of the fact that their information is being shared. Additionally, some of the data is unencrypted, which allows for more substantial problems to arise.
So when I look into an app, I’m usually looking for connections, databases, data gathered by the app, and any potential security holes that would allow users to slip into the program’s inner communications.
Speaking of hacking, please tell us what are some of the ways black hat can hack into applications or systems with the intention to cause serious harm?
As a bad guy, you can approach attacks from different levels:
1) On the device
It is possible to look into poorly programmed apps using a device. Take the Nissan app that you’ve recently covered as an example. In general, certain apps have open back doors, allowing individuals to obtain information from other apps. Alternatively, the app could be gathering data itself and sending it over an unsecured path.
2) In transit
Every app or system tries to communicate with other systems or servers, and all of this traffic can easily be intercepted. On top of that, the traffic might be unencrypted, making it even more easily readable. Alternatively, it could simply be poorly encrypted, allowing anyone with a little bit of skill to figure out what‘s going on.
3) In the cloud or on the server
If you’re able to figure out how traffic works using the tools mentioned in the previous two steps, then it shouldn‘t be that difficult to send or gather information you want over the Cloud or on a server.
What do you think about government and legitimate businesses "spying" on the citizens and customers e.g. the recent scandal about the Deutsche Telekom?
Unfortunately, the scandal involving Deutsche Telekom is just the tip of the iceberg when it comes to cases like these. Mass data breaches are a worldwide problem, as is explicitly shown in this article. For each breach that we’ve uncovered, there are handfuls more that remain undiscovered.
On one hand, it is understandable that a certain kind of “spying“ is necessary for security reasons, but it is often abused to steal data or source code from companies. Even security companies are of interest to governments and hackers – recently, the U.S. government was found to be spying on a collection of antivirus companies, some of which are household names across the globe. It is a thin line that exists between spying for security reasons and spying for personal gain.
The biggest issue is that this area is still quite new, and we still lack laws to sufficiently and effectively regulate the system.
When we tell people that we are doing security, the first thing the majority of people ask if we are antivirus, which is the specialty of Avast, your current company. If you have to say one short sentence to distinguish antivirus and our solution, what is it?
TeskaLabs' solution prevents data being hacked and stolen during data transit and handles data in a secure way while antivirus software mainly protects devices against infections.
~ Interviewed by Cindy Dam ~
You Might Be Interested in Reading These Articles
Our Business Development Manager, Pavel Enderle, had an interview with CT24 TV, a Czech television channel, to discuss cloud security regarding the new Barbie product, Hello Barbie. This Barbie can talk to children by using ToyTalk’s system to analyze the child’s speech and produce relevant responses.
Published on June 09, 2015
How TeskaLabs Helped O2 Improve Customer Satisfaction of eKasa Point-of-Sale (POS), the Most Successful POS Product / Mobile Cash Register on the Czech Market
In 2016 the Czech government introduced a new law that required businesses to report their sales and provide Electronic Evidence of Sales (EET). This law calls for the adoption of a more modern point-of-sale system that enables businesses to meet regulatory requirements set forth under this law. During the next two years, the law will gradually impact more than three hundred thousand companies in the Czech Republic. O2, the largest integrated telecommunications provider in the Czech market, observed that many would need help complying with this law, maintaining data security and demanding excellent customer support.
Published on August 08, 2017
Is There A Network Protocol for Your Mobile Apps That Offers A Higher Security Level While Consuming Less Bandwidth Than HTTPS? Yes, There Is
For mobile apps or websites that don’t have logins, forms or features to extract data, you don’t need secure access. For banking websites, mobile apps and mobile banking services, without a doubt, secure communication is a must. But nothing is ever black and white.
Published on September 13, 2016