SlideShare a Scribd company logo
1
Roberto Martelloni,
Digital Banking and Mobile Payments Summit, April 2017, Vienna
CI
IoT, Point Of Sales And Mobile
devices
different names, same
Information Security & Privacy
concerns
22
WHO AM I?
Roberto Martelloni
VP, Global Mobile Security @ CITI
COBIT®5(F), CISM, CISSP, CCSP, CSSLP, CSPO, CSM
certified with 17 years of professional experience in
Information and Cyber Security
Experience ranging from a startup to mastodontic
corporations, from niche sectors (lawful interception) to
economy driving areas (Defence, Oil and Gas, and Finance)
and also to the North Atlantic Treaty Organization (NATO).
33
WHAT AM I GOING TO TALK ABOUT?
IoT, Point of Sale, and Mobile
How these three apparent different fields are instead
very similar
What they share in term of information security and
privacy concerns
44
AGENDA
1. IoT technology overview
2. Point of Sale technology overview
3. Mobile technology overview
4. Differences and similarities
5. Common Information security and privacy
concerns
6. Questions
55
WHAT IS AN INTERNET OF THING?
The Internet of things (IoT) is the internetworking of
physical devices, vehicles (also referred to as "connected
devices" and "smart devices"), buildings, and other items—
embedded with electronics, software, sensors, actuators,
and network connectivity that enable these objects to
collect and exchange data.
(Wikipedia)
66
IoT - WEARABLE
Apple Watch
LG Watch
77
IoT - SMART HOME
88
IoT - SMART HOME
Nest Learning Thermostat Honeywell Smart Thermostat
99
IoT - SMART OFFICE
Axessor IP LOCK Ucam 247
1010
IoT - SMART TOYS (!)
CloudPets
1111
IoT - UNDER THE HOOD
1212
IoT - OPERATING SYSTEM
IoT Developer Survey 2016
(Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
1313
IoT - PROTOCOLS
Few words on Peripherals
IoT Developer Survey 2016
(Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
1414
IoT - CLOUD
Few words on Peripherals
IoT Developer Survey 2016
(Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
1515
WHAT IS AN INTERNET OF THING?
Device
+
Common operating system
+
Common or less common protocols
+
Cloud
+
Exotic Input/Output peripherals
=
Internet of things
(Roberto)
1616
WHAT IS AN INTERNET OF THING (DETAILS)
# IoT
Software
Operating System Linux
Hardening No
Framework Custom
Cloud Yes
Wire
Serial Maybe
Ethernet Yes
USB Maybe
Wireless
GPS Maybe
Cellular Maybe
Wi-Fi Yes
Bluetooth Maybe
NFC Maybe
Peripherals
Card Reader Maybe
Biometric Maybe
Exotic I/O peripherals Yes
1717
WHAT IS A POINT OF SALE?
A payment terminal, also known as a point of sale
terminal (PoS), credit card terminal, EFTPOS terminal (or
a PDQ terminal in the United Kingdom), is a device which
interfaces with payment cards to make electronic funds
transfers.
(Wikipedia)
1818
POINT OF SALE – BIGGEST PLAYERS
1919
POINT OF SALE
DESK 5000 P400
2020
MOBILE POINT OF SALE
iSMP4 e355
2121
POINT OF SALE – UNDER THE HOOD
2222
POINT OF SALE - OPERATING SYSTEM
+
2323
POINT OF SALE - SECURITY
2424
POINT OF SALE - PROTOCOLS
2525
POINT OF SALE - CLOUD: MARKETPLACE and APPS
https://www.ingenico.com/marketplace
2626
WHAT IS A POINT OF SALE?
Device (with hardening!)
+
Common operating system (with hardening!)
+
Common protocols
+
Cloud
+
Input/Output peripherals
=
Point of Sale
(Roberto)
2727
WHAT IS A POINT OF SALE (DETAILS)
# Point of Sale
Software
Operating System Linux
Hardening Yes
Framework Custom
Cloud Yes
Wire
Serial Maybe
Ethernet Yes
USB Yes
Wire
GPS No
Cellular Maybe
Wi-Fi Yes
Bluetooth Yes
NFC Yes
Peripherals
Card Reader Yes
Biometric No
Exotic I/O peripherals No
2828
WHAT IS A MOBILE DEVICE?
A small computing device, having an operating
system capable of running mobile apps, a display
screen, alphanumeric keyboard or a touchscreen and
buttons (icons) on-screen. Many such devices can connect to
the Internet and other devices via Wi-Fi, Bluetooth or near
field communication (NFC). Integrated cameras, digital
media players, mobile phone and GPS capabilities.
(Wikipedia)
2929
WHAT IS A MOBILE DEVICE?
Google Pixel
3030
WHAT IS A MOBILE DEVICE?
Few Mobile Device pictures and market overview
Pixel C
3131
WHAT IS A MOBILE DEVICE?
HUAWEI MediaPad M3 HUAWEI MediaPad T1
3232
MOBILE - UNDER THE HOOD
3333
MOBILE - OPERATING SYSTEM
Android iOS
3434
MOBILE - OPERATING SYSTEM
Linux BSD (Unix)
3535
MOBILE - OPERATING SYSTEM: EXPLOIT MARKET
https://www.zerodium.com/program.html
3636
MOBILE - PROTOCOLS
3737
MOBILE - CLOUD
3838
WHAT IS A MOBILE DEVICE?
Device
+
Common operating system (with super hardening!)
+
Common protocols
+
Cloud (!)
+
Input/Output peripherals
=
Mobile Device
(Roberto)
3939
WHAT IS A MOBILE DEVICE (DETAILS)
# Mobile
Software
Operating System Linux / Unix
Hardening Yes
Framework Android / iOS
Cloud Yes
Wire
Serial No
Ethernet No
USB Yes
Wire
GPS Yes
Cellular Yes
Wi-Fi Yes
Bluetooth Yes
NFC Yes
Peripherals
Card Reader No
Biometric Yes
Exotic I/O peripherals No
4040
IoT, PoS and Mobile - UNDER THE HOOD
4141
WHAT ARE IoT, PoS and MOBILE DEVICE?
Device
+
Common operating system
+
Common protocols
+
Cloud
+
Input/Output peripherals
=
IoT, PoS, and Mobile Device
(Roberto)
4242
IOT, POINT OF SALE, MOBILE COMPARISON
# IoT Point of Sale Mobile
Software
Operating System Linux Linux Linux / Unix
Hardening No Yes Yes
Framework Custom Custom Android / iOS
Cloud Yes Maybe Yes
Wire
Serial Maybe Maybe No
Ethernet Yes Yes No
USB Maybe Yes Yes
Wireless
GPS Maybe No Yes
Cellular Maybe Maybe Yes
Wi-Fi Yes Yes Yes
Bluetooth Maybe Yes Yes
NFC Maybe Yes Yes
Peripherals
Card Reader Maybe Yes No
Biometric Maybe No Yes
Exotic I/O peripherals Yes No No
4343
INFORMATION SECURITY
NISTIR 8144
Assessing Threats to Mobile Devices &
Infrastructure
Mobile Threat Catalogue
4444
MOBILE - THREAT CATALOGUE CATEGORIES
Physical
Access
Technology
Stack
Application
Authentication EMM Ecosystem
GPS Cellular LAN & PAN
Payment Supply Chain
45
THANK YOU!
Email: roberto.martelloni@citi.com

More Related Content

PDF
Zinnov Zones for IoT Services 2017
PPTX
Iot basics & evolution of 3 gpp technolgies for iot connectivity
PDF
M2M transitioning to IoT opportunity for telcos. Success references.
PDF
IoT Convention Europe - Mechelen June 15th 2017
PPTX
Connected Futures Cisco Research: IoT Value: Challenges, Breakthroughs, and B...
PDF
Oies IoT World Europe 20170615
PDF
Industry 4.0 Smart Factory IoT Solutions- building the digital enterprise to ...
PPTX
Internet of things cisco
Zinnov Zones for IoT Services 2017
Iot basics & evolution of 3 gpp technolgies for iot connectivity
M2M transitioning to IoT opportunity for telcos. Success references.
IoT Convention Europe - Mechelen June 15th 2017
Connected Futures Cisco Research: IoT Value: Challenges, Breakthroughs, and B...
Oies IoT World Europe 20170615
Industry 4.0 Smart Factory IoT Solutions- building the digital enterprise to ...
Internet of things cisco

What's hot (20)

PDF
IoT: Understanding its potential and what makes it tick! by Mark Torr
PDF
C white cisco_livecancun_nov_press
PDF
Oracle Digital Business Transformation and Internet of Things by Ermin Prašović
PDF
PRG Symposium From Idea to Scale vF
PDF
Zinnov 2015 Quarterly PES Landscape Analysis - (Q1)
PDF
Keynote Presentation by Pablo Iacopino, GSMA Intelligence: 5G is coming – But...
PPTX
Industrial IOT By Rishika Ghosh
PDF
Opening keynote by Peter Jarich, GSMA Intelligence: GSMA Intelligence 2.0 – D...
PPTX
Cisco Mobility - IBM & IDC event
PPTX
Revolutionize your business with the Industrial Internet of Things ( IIoT) - ...
PDF
IoT Slam Keynote: The Rise of the IoT Application with Chris O'Connor
PPTX
The Internet of Things - beyond the hype and towards ROI
PDF
IoT and Embedded OS Lecture - Cristian Toma and George Iosif
PDF
GSMA Intelligence Webinar - 27 November 2018
PPTX
IoT now: From Things to Outcomes
PDF
IoT and AI
PPTX
É possível existir segurança para IoT?
PDF
Gartner TOP 10 Strategic Technology Trends 2017
PPTX
2016 IoT Insights and Opportunities
PDF
[Webinar] – Social Distancing Radar: Smart AI Solution to Restart Your Business
IoT: Understanding its potential and what makes it tick! by Mark Torr
C white cisco_livecancun_nov_press
Oracle Digital Business Transformation and Internet of Things by Ermin Prašović
PRG Symposium From Idea to Scale vF
Zinnov 2015 Quarterly PES Landscape Analysis - (Q1)
Keynote Presentation by Pablo Iacopino, GSMA Intelligence: 5G is coming – But...
Industrial IOT By Rishika Ghosh
Opening keynote by Peter Jarich, GSMA Intelligence: GSMA Intelligence 2.0 – D...
Cisco Mobility - IBM & IDC event
Revolutionize your business with the Industrial Internet of Things ( IIoT) - ...
IoT Slam Keynote: The Rise of the IoT Application with Chris O'Connor
The Internet of Things - beyond the hype and towards ROI
IoT and Embedded OS Lecture - Cristian Toma and George Iosif
GSMA Intelligence Webinar - 27 November 2018
IoT now: From Things to Outcomes
IoT and AI
É possível existir segurança para IoT?
Gartner TOP 10 Strategic Technology Trends 2017
2016 IoT Insights and Opportunities
[Webinar] – Social Distancing Radar: Smart AI Solution to Restart Your Business
Ad

Similar to IoT, PoS and Mobile Devices different names same privacy and information security concerns (20)

PPTX
Internet Of Things What You Need To Know - TechFuse
PPTX
Emerging Global Trends in IoT (Internet of things)
DOCX
INST560, Internet of Things (IoT)UNIVERSITY OF NORTH AMERICA.docx
PDF
Enterprise IT and the Internet of Things
PPTX
Compiler design presentaion
PPTX
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
PPTX
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
PPTX
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
PPTX
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
PPTX
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
PDF
IoTShow.in Bangalore 2019 - a Recap on 'IoT and Edge' Talk.
PPTX
IOT . .
PPT
IoTConcept&Architecture.grt kerning gud to seeppt
PPTX
iotskppt on internet of things for information.pptx
PDF
IoT: The T is for Telco, Isn't it?
PPTX
Iot trends and technologies development in terms of Machine Learning
PDF
Avnet Silica at SIDO Lyon
PDF
Top 10 trends of internet of things in 2020
PPTX
Introduction Internet of Things (IoT).pptx
PDF
Internet of Things - The Battle for your Home, Commute, and Life
Internet Of Things What You Need To Know - TechFuse
Emerging Global Trends in IoT (Internet of things)
INST560, Internet of Things (IoT)UNIVERSITY OF NORTH AMERICA.docx
Enterprise IT and the Internet of Things
Compiler design presentaion
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
02_Internet-of-things-IOT-by-Davis-M-Onsakia_ISOC-IoT-SIG.pptx
IoTShow.in Bangalore 2019 - a Recap on 'IoT and Edge' Talk.
IOT . .
IoTConcept&Architecture.grt kerning gud to seeppt
iotskppt on internet of things for information.pptx
IoT: The T is for Telco, Isn't it?
Iot trends and technologies development in terms of Machine Learning
Avnet Silica at SIDO Lyon
Top 10 trends of internet of things in 2020
Introduction Internet of Things (IoT).pptx
Internet of Things - The Battle for your Home, Commute, and Life
Ad

Recently uploaded (20)

PPTX
A Presentation on Artificial Intelligence
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
Hindi spoken digit analysis for native and non-native speakers
PDF
Getting Started with Data Integration: FME Form 101
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
project resource management chapter-09.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PPTX
A Presentation on Touch Screen Technology
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
Encapsulation theory and applications.pdf
PPTX
1. Introduction to Computer Programming.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
A comparative study of natural language inference in Swahili using monolingua...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
Hybrid model detection and classification of lung cancer
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Mushroom cultivation and it's methods.pdf
A Presentation on Artificial Intelligence
Heart disease approach using modified random forest and particle swarm optimi...
Univ-Connecticut-ChatGPT-Presentaion.pdf
Hindi spoken digit analysis for native and non-native speakers
Getting Started with Data Integration: FME Form 101
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
project resource management chapter-09.pdf
Group 1 Presentation -Planning and Decision Making .pptx
SOPHOS-XG Firewall Administrator PPT.pptx
A Presentation on Touch Screen Technology
cloud_computing_Infrastucture_as_cloud_p
Encapsulation theory and applications.pdf
1. Introduction to Computer Programming.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
A comparative study of natural language inference in Swahili using monolingua...
Programs and apps: productivity, graphics, security and other tools
Zenith AI: Advanced Artificial Intelligence
Hybrid model detection and classification of lung cancer
Encapsulation_ Review paper, used for researhc scholars
Mushroom cultivation and it's methods.pdf

IoT, PoS and Mobile Devices different names same privacy and information security concerns

  • 1. 1 Roberto Martelloni, Digital Banking and Mobile Payments Summit, April 2017, Vienna CI IoT, Point Of Sales And Mobile devices different names, same Information Security & Privacy concerns
  • 2. 22 WHO AM I? Roberto Martelloni VP, Global Mobile Security @ CITI COBIT®5(F), CISM, CISSP, CCSP, CSSLP, CSPO, CSM certified with 17 years of professional experience in Information and Cyber Security Experience ranging from a startup to mastodontic corporations, from niche sectors (lawful interception) to economy driving areas (Defence, Oil and Gas, and Finance) and also to the North Atlantic Treaty Organization (NATO).
  • 3. 33 WHAT AM I GOING TO TALK ABOUT? IoT, Point of Sale, and Mobile How these three apparent different fields are instead very similar What they share in term of information security and privacy concerns
  • 4. 44 AGENDA 1. IoT technology overview 2. Point of Sale technology overview 3. Mobile technology overview 4. Differences and similarities 5. Common Information security and privacy concerns 6. Questions
  • 5. 55 WHAT IS AN INTERNET OF THING? The Internet of things (IoT) is the internetworking of physical devices, vehicles (also referred to as "connected devices" and "smart devices"), buildings, and other items— embedded with electronics, software, sensors, actuators, and network connectivity that enable these objects to collect and exchange data. (Wikipedia)
  • 6. 66 IoT - WEARABLE Apple Watch LG Watch
  • 8. 88 IoT - SMART HOME Nest Learning Thermostat Honeywell Smart Thermostat
  • 9. 99 IoT - SMART OFFICE Axessor IP LOCK Ucam 247
  • 10. 1010 IoT - SMART TOYS (!) CloudPets
  • 11. 1111 IoT - UNDER THE HOOD
  • 12. 1212 IoT - OPERATING SYSTEM IoT Developer Survey 2016 (Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
  • 13. 1313 IoT - PROTOCOLS Few words on Peripherals IoT Developer Survey 2016 (Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
  • 14. 1414 IoT - CLOUD Few words on Peripherals IoT Developer Survey 2016 (Eclipse IoT Working Group, IEEE IoT and AGILE IoT)
  • 15. 1515 WHAT IS AN INTERNET OF THING? Device + Common operating system + Common or less common protocols + Cloud + Exotic Input/Output peripherals = Internet of things (Roberto)
  • 16. 1616 WHAT IS AN INTERNET OF THING (DETAILS) # IoT Software Operating System Linux Hardening No Framework Custom Cloud Yes Wire Serial Maybe Ethernet Yes USB Maybe Wireless GPS Maybe Cellular Maybe Wi-Fi Yes Bluetooth Maybe NFC Maybe Peripherals Card Reader Maybe Biometric Maybe Exotic I/O peripherals Yes
  • 17. 1717 WHAT IS A POINT OF SALE? A payment terminal, also known as a point of sale terminal (PoS), credit card terminal, EFTPOS terminal (or a PDQ terminal in the United Kingdom), is a device which interfaces with payment cards to make electronic funds transfers. (Wikipedia)
  • 18. 1818 POINT OF SALE – BIGGEST PLAYERS
  • 20. 2020 MOBILE POINT OF SALE iSMP4 e355
  • 21. 2121 POINT OF SALE – UNDER THE HOOD
  • 22. 2222 POINT OF SALE - OPERATING SYSTEM +
  • 23. 2323 POINT OF SALE - SECURITY
  • 24. 2424 POINT OF SALE - PROTOCOLS
  • 25. 2525 POINT OF SALE - CLOUD: MARKETPLACE and APPS https://www.ingenico.com/marketplace
  • 26. 2626 WHAT IS A POINT OF SALE? Device (with hardening!) + Common operating system (with hardening!) + Common protocols + Cloud + Input/Output peripherals = Point of Sale (Roberto)
  • 27. 2727 WHAT IS A POINT OF SALE (DETAILS) # Point of Sale Software Operating System Linux Hardening Yes Framework Custom Cloud Yes Wire Serial Maybe Ethernet Yes USB Yes Wire GPS No Cellular Maybe Wi-Fi Yes Bluetooth Yes NFC Yes Peripherals Card Reader Yes Biometric No Exotic I/O peripherals No
  • 28. 2828 WHAT IS A MOBILE DEVICE? A small computing device, having an operating system capable of running mobile apps, a display screen, alphanumeric keyboard or a touchscreen and buttons (icons) on-screen. Many such devices can connect to the Internet and other devices via Wi-Fi, Bluetooth or near field communication (NFC). Integrated cameras, digital media players, mobile phone and GPS capabilities. (Wikipedia)
  • 29. 2929 WHAT IS A MOBILE DEVICE? Google Pixel
  • 30. 3030 WHAT IS A MOBILE DEVICE? Few Mobile Device pictures and market overview Pixel C
  • 31. 3131 WHAT IS A MOBILE DEVICE? HUAWEI MediaPad M3 HUAWEI MediaPad T1
  • 33. 3333 MOBILE - OPERATING SYSTEM Android iOS
  • 34. 3434 MOBILE - OPERATING SYSTEM Linux BSD (Unix)
  • 35. 3535 MOBILE - OPERATING SYSTEM: EXPLOIT MARKET https://www.zerodium.com/program.html
  • 38. 3838 WHAT IS A MOBILE DEVICE? Device + Common operating system (with super hardening!) + Common protocols + Cloud (!) + Input/Output peripherals = Mobile Device (Roberto)
  • 39. 3939 WHAT IS A MOBILE DEVICE (DETAILS) # Mobile Software Operating System Linux / Unix Hardening Yes Framework Android / iOS Cloud Yes Wire Serial No Ethernet No USB Yes Wire GPS Yes Cellular Yes Wi-Fi Yes Bluetooth Yes NFC Yes Peripherals Card Reader No Biometric Yes Exotic I/O peripherals No
  • 40. 4040 IoT, PoS and Mobile - UNDER THE HOOD
  • 41. 4141 WHAT ARE IoT, PoS and MOBILE DEVICE? Device + Common operating system + Common protocols + Cloud + Input/Output peripherals = IoT, PoS, and Mobile Device (Roberto)
  • 42. 4242 IOT, POINT OF SALE, MOBILE COMPARISON # IoT Point of Sale Mobile Software Operating System Linux Linux Linux / Unix Hardening No Yes Yes Framework Custom Custom Android / iOS Cloud Yes Maybe Yes Wire Serial Maybe Maybe No Ethernet Yes Yes No USB Maybe Yes Yes Wireless GPS Maybe No Yes Cellular Maybe Maybe Yes Wi-Fi Yes Yes Yes Bluetooth Maybe Yes Yes NFC Maybe Yes Yes Peripherals Card Reader Maybe Yes No Biometric Maybe No Yes Exotic I/O peripherals Yes No No
  • 43. 4343 INFORMATION SECURITY NISTIR 8144 Assessing Threats to Mobile Devices & Infrastructure Mobile Threat Catalogue
  • 44. 4444 MOBILE - THREAT CATALOGUE CATEGORIES Physical Access Technology Stack Application Authentication EMM Ecosystem GPS Cellular LAN & PAN Payment Supply Chain