R
Ryan Lloyd
Actor
5
APPEARANCES
5
PODCASTS
024
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
Jul 7, 2026
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
28:38
28:55
29:05
29:22
29:37
37:30

Mike SchemaHOST
What does it look like for, or what, how difficult is it, what should developers keep in mind if the AppSec team comes and says, "We need to secure our mobile app"? Which I understand is pretty generic and probably over-broad, but help me make that more granular and more actionable for, for that developer team.

Ryan LloydGUEST
Yeah, I think the, the answer is in having these different layers that can complement each other and work together in, in protecting your application.

Ryan LloydGUEST
And then, you know, an area that we've spent a lot of time researching and focusing in on is, um, this concept of really applying it at the compiler level to the applications that we're protecting.

Ryan LloydGUEST
Some strategies would be to encrypt the application itself and have some startup code and whatnot that, um, decrypts the application while it's running, and that works well, but that's, that's what we would characterize as a single layer of app protection.

Ryan LloydGUEST
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic, and if you manage to manipulate that, you've now got a way to bypass that protection, uh, layer.
8 MINS LATER

Mike SchemaHOST
Are there things there that could, that the OS itself could do that would help mobile developers, you know, have, have better attestation, better confidence, better trust, or is this very much the responsibility of the, the mobile app itself?
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
28:39
28:55
29:05
29:22
29:37
37:30

Mike ShimaHOST
Or what, how difficult is it? What should developers keep in mind if the AppSec team comes and says, "We need to secure our mobile app," which I understand is pretty generic and probably over-broad, but help me make that more granular and more actionable for, for that developer team.

Ryan LloydGUEST
Yeah, I think the, the answer is in having these different layers that can complement each other and work together in, in protecting your application.

Ryan LloydGUEST
And then, you know, an area that we've spent a lot of time researching and focusing in on is, um, this concept of really applying it at the compiler level to the applications that we're protecting.

Ryan LloydGUEST
Some strategies would be to encrypt the application itself and have some startup code and whatnot that, um, decrypts the application while it's running, and that works well, but that's, that's what we would characterize as a single layer of app protection.

Ryan LloydGUEST
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic.
8 MINS LATER

Mike ShimaHOST
Are there things there that could, that the OS itself could do that would help mobile developers, you know, have, have better attestation, better confidence, better trust, or is this very much the responsibility of the, the mobile app itself?
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
28:38
28:55
29:05
29:22
29:31
29:37
37:30

Mike SchemaHOST
What does it look like for, how difficult is it? What should developers keep in mind if the AppSec team comes and says, we need to secure our mobile app, which I understand is pretty generic and probably overbroad, but help me make that more granular and more actionable for that developer team.

Ryan LloydGUEST
Yeah, I think the answer is in having these different layers that can complement each other and work together in protecting your application.

Ryan LloydGUEST
And then an area that we've spent a lot of time researching and focusing in on is this concept of really applying it at the compiler level to the applications that we're protecting.

Ryan LloydGUEST
Some strategies would be to encrypt the application itself and have some startup code and whatnot that decrypts the application while it's running.

Ryan LloydGUEST
And that works well, but that's what we would characterize as a single layer of app protection.

Ryan LloydGUEST
So it's encrypted, which is great, except that that encryption key is obfuscated somewhere in that startup logic.
8 MINS LATER

Mike SchemaHOST
Are there things there that the OS itself could do that would help mobile developers have better attestation, better confidence, better trust? Or is this very much the responsibility of the mobile app itself?
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
28:38
28:55
29:05
29:22
29:32
37:30

Mike SchemaHOST
What does it look like for, how difficult is it? What should developers keep in mind if the AppSec team comes and says, we need to secure our mobile app, which I understand is pretty generic and probably overbroad, but help me make that more granular and more actionable for that developer team.

Ryan LloydGUEST
Yeah, I think the answer is in having these different layers that can complement each other and work together in protecting your application.

Ryan LloydGUEST
And then an area that we've spent a lot of time researching and focusing in on is this concept of really applying it at the compiler level to the applications that we're protecting.

Ryan LloydGUEST
Some strategies would be to encrypt the application itself and have some startup code and whatnot that decrypts the application while it's running.

Ryan LloydGUEST
And that works well, but that's what we would characterize as a single layer of app protection.
8 MINS LATER

Mike SchemaHOST
Are there things there that the OS itself could do that would help mobile developers have better attestation, better confidence, better trust? Or is this very much the responsibility of the mobile app itself?
5.29.2026 - America 250, Fourth Verse, Trump Fatigue
22:00
22:14
22:36
22:56
23:35

Ryan LloydGUEST
Yeah, so I'm a 27-year Army veteran, and like a lot of veterans, the Star-Spangled Banner is near and dear to my heart.

Ryan LloydGUEST
And having deployed to Iraq a couple times, I can tell you that Uh, I've probably been moved to tears by the national anthem more than most adults, but there's something special about the fourth verse of the national anthem that is, is not really conveyed by what we normally hear out there with, you know, just the first verse.

Ryan LloydGUEST
Um, it talks about, you know, the first verse talks about American resilience and, uh, you know, it sets the, the tone for that, uh, Battle of Fort McHenry.

Ryan LloydGUEST
So the Why We Stand project that I'm starting is to... convey that really deep why, and it conveys American exceptionalism and, you know, providential, you know, support of the United States that I don't think you get from verse one.

Ryan LloydGUEST
So I do have a Facebook page called the Why We Stand Project, and you can find it on Instagram, too.
