Skip to main content

Ryan Lloyd

Actor

Jul 7, 2026

28:38
What does it look like for, or what, how difficult is it, what should developers keep in mind if the AppSec team comes and says, "We need to secure our mobile app"? Which I understand is pretty generic and probably over-broad, but help me make that more granular and more actionable for, for that developer team.
28:55
Yeah.
28:55
Yeah, I think the, the answer is in having these different layers that can complement each other and work together in, in protecting your application.
29:05
And then, you know, an area that we've spent a lot of time researching and focusing in on is, um, this concept of really applying it at the compiler level to the applications that we're protecting.
29:18
Um, so there's different strategies for how you can protect an application.
29:22
Some strategies would be to encrypt the application itself and have some startup code and whatnot that, um, decrypts the application while it's running, and that works well, but that's, that's what we would characterize as a single layer of app protection.
29:37
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic, and if you manage to manipulate that, you've now got a way to bypass that protection, uh, layer.

8 MINS LATER

37:30
Are there things there that could, that the OS itself could do that would help mobile developers, you know, have, have better attestation, better confidence, better trust, or is this very much the responsibility of the, the mobile app itself?
28:39
Or what, how difficult is it? What should developers keep in mind if the AppSec team comes and says, "We need to secure our mobile app," which I understand is pretty generic and probably over-broad, but help me make that more granular and more actionable for, for that developer team.
28:55
Yeah.
28:55
Yeah, I think the, the answer is in having these different layers that can complement each other and work together in, in protecting your application.
29:05
And then, you know, an area that we've spent a lot of time researching and focusing in on is, um, this concept of really applying it at the compiler level to the applications that we're protecting.
29:18
Um, so there's different strategies for how you can protect an application.
29:22
Some strategies would be to encrypt the application itself and have some startup code and whatnot that, um, decrypts the application while it's running, and that works well, but that's, that's what we would characterize as a single layer of app protection.
29:37
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic.

8 MINS LATER

37:30
Are there things there that could, that the OS itself could do that would help mobile developers, you know, have, have better attestation, better confidence, better trust, or is this very much the responsibility of the, the mobile app itself?
28:38
What does it look like for, how difficult is it? What should developers keep in mind if the AppSec team comes and says, we need to secure our mobile app, which I understand is pretty generic and probably overbroad, but help me make that more granular and more actionable for that developer team.
28:55
Yeah, I think the answer is in having these different layers that can complement each other and work together in protecting your application.
29:05
And then an area that we've spent a lot of time researching and focusing in on is this concept of really applying it at the compiler level to the applications that we're protecting.
29:19
So there's different strategies for how you can protect an application.
29:22
Some strategies would be to encrypt the application itself and have some startup code and whatnot that decrypts the application while it's running.
29:31
And that works well, but that's what we would characterize as a single layer of app protection.
29:37
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic.

8 MINS LATER

37:30
Are there things there that the OS itself could do that would help mobile developers have better attestation, better confidence, better trust? Or is this very much the responsibility of the mobile app itself?
28:38
What does it look like for, how difficult is it? What should developers keep in mind if the AppSec team comes and says, we need to secure our mobile app, which I understand is pretty generic and probably overbroad, but help me make that more granular and more actionable for that developer team.
28:55
Yeah, I think the answer is in having these different layers that can complement each other and work together in protecting your application.
29:05
And then an area that we've spent a lot of time researching and focusing in on is this concept of really applying it at the compiler level to the applications that we're protecting.
29:19
So there's different strategies for how you can protect an application.
29:22
Some strategies would be to encrypt the application itself and have some startup code and whatnot that decrypts the application while it's running.
29:32
And that works well, but that's what we would characterize as a single layer of app protection.
29:37
So it's encrypted, which is great.

8 MINS LATER

37:30
Are there things there that the OS itself could do that would help mobile developers have better attestation, better confidence, better trust? Or is this very much the responsibility of the mobile app itself?
21:58
So fill us in.
22:00
Yeah, so I'm a 27-year Army veteran, and like a lot of veterans, the Star-Spangled Banner is near and dear to my heart.
22:14
And having deployed to Iraq a couple times, I can tell you that Uh, I've probably been moved to tears by the national anthem more than most adults, but there's something special about the fourth verse of the national anthem that is, is not really conveyed by what we normally hear out there with, you know, just the first verse.
22:36
Um, it talks about, you know, the first verse talks about American resilience and, uh, you know, it sets the, the tone for that, uh, Battle of Fort McHenry.
22:50
And the fourth verse, though, really conveys the why behind it.
22:56
So the Why We Stand project that I'm starting is to... convey that really deep why, and it conveys American exceptionalism and, you know, providential, you know, support of the United States that I don't think you get from verse one.
23:30
Ryan, how can people find out more about this and become part of this?
23:35
So I do have a Facebook page called the Why We Stand Project, and you can find it on Instagram, too.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.