Matomo

End-to-end encryption for remote debugging tool | Cossack Labs
Case studies
End-to-end encryption for remote debugging tool

End-to-end encryption for remote debugging tool

2018 Software application Application level encryption
End-to-end encryption for remote debugging tool

Overview

Industry

  • B2B solution for software engineering teams

Technology stack

  • iOS
  • Android
  • Electron
  • PostgreSQL

Regulations

  • GDPR
  • Encryption Export Regulations
  • Android privacy policy guidance

Challenges

[01]

Different types of sensitive data

AppSpector system operates on multiple types of data: user data, data generated from devices, data generated in monitoring dashboard. All these data types are processed in different infrastructural components, all of which require protection.

[02]

Multi-device synchronisation

Mobile users own multiple devices, some of them online, and some are offline at different moments, which requires careful synchronisation of encrypted data and keys.

[03]

Numerous data sources

App-specific data can contain personal user data, upcoming application features, logs, data from internal database and Keychain/KeyStore, screenshots.

[04]

Customer's data isolation and insider risks

Data protection should isolate customers' data in shared environments from each other, yet allow users to have access to multiple teams and applications. The security solution should protect customers' data from insiders and outside attackers.

Technology requirements

Technology requirements

Protect the data from mobile SDK to dashboard

Data protection throughout the whole data flow of the system (Android SDK, iOS SDK, Electron app, web backend) with similar security controls to provide stronger security and better maintainability.

Easy to maintain encryption engine

Easy to maintain encryption engine, which can be maintained and updated by non-cryptographers without the risk of breaking cryptography, giving AppSpector team flexibility to introduce changes.

Solution

Security risk management and risk assessment:

We've designed end-to-end encryption engine that has the following properties:

Results and outcomes

Our solution satisfies security requirements, isolates and protects sensitive data on different levels, and uses end-to-end encryption and traditional security controls.

The security system went through mobile and Electron platforms and was released simultaneously. Our engineers worked closely with AppSpector engineers, designing the cryptographic layer, assisting with implementation, suggesting and verifying security controls.

Deep integration of the security layer allowed AppSpector to target large enterprise customers and security-conscious users and distinguish their product from competitors.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days