BSidesLV has ended
Thank you for joining us for our 5th Anniversary celebration! We certainly hope you enjoy the conference. Here’s to Education, Collaboration, and Community!

Remember, we don’t take ourselves too seriously and you shouldn’t, either! To quote the old motto of another collaborative community, "We trick into learning with a laugh".

We wish you both laughter and learning - and lots of both!

-= Team BSidesLV 
Back To Schedule
Wednesday, August 6 • 10:00 - 10:30
iOS URL Schemes: omg://

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Have you ever clicked a phone number in Safari to get the phone app to call that store/car dealership/pizza place you were searching for?

In iOS, this interaction between apps happens via URL schemes, which are available to Apple applications as well as third party applications. Everyone uses them without noticing they exist. They are the most flexible of the imperfect methods available right now.

They are, however, a source of user input that should never be trusted as safe. In this presentation, we will look at real life examples of implementations of URL Schemes that could lead to issues such as destruction of data or help a malicious person identify an iOS user.

We will also look at simple ways to improve URL Scheme security for users of your apps as well as how to find URL Scheme vulnerabilities, for the ones out there who would like to help out.

avatar for Guillaume Ross

Guillaume Ross

Security Researcher, Uptycs
Guillaume Ross is an IT and security expert, passionate about Macs. With 20+ years of experience, he understands latest cyber threats & helps stay protected. Bio writing is not his thing, so he relied on AI. Valuable in today's ever-evolving digital landscape, his expertise is an... Read More →

Wednesday August 6, 2014 10:00 - 10:30 PDT
Tuscany Suites 255 E. Flamingo Rd. Las Vegas, NV

Attendees (0)