Why your smartphone knows more about you than you think it does
📘 Free e-book: The 7 success factors of software testing. 25 years of project experience in one 33-page workbook, now also in English 👉 Get it for free
"Attackers know what apps we are working with, we are using, and they take advantage of it." - Bartosz Czernic-Goławski
In this episode, I talk with Bartosz Czernic-Goławski, a penetration testing and cybersecurity expert, about how mobile security has evolved from Nokia's indestructible brick phones to today's pocket-sized computers. We trace the journey from analog networks that anyone could eavesdrop on to modern smartphones that demand excessive permissions and collect sensor data every second. Bartosz reveals how attackers use overlay attacks to steal banking credentials, why iOS users aren't as secure as they think, and what phone freaks in the 1980s can teach us about today's vulnerabilities.
Bartosz Czernic-Goławski is a non-functional tester with six years of professional experience, currently working at Pentacomp as a security auditor and penetration tester. He holds an Engineering degree in Telecommunications and a Master’s degree in Applied Computer Science with a specialization in Cybersecurity—both earned at the Warsaw University of Technology.
In his work, he focuses on the security testing of systems developed by Pentacomp, as well as conducting penetration tests and audits for external organizations. Commercially, he has tested mobile, web, and desktop applications, as well as IT and OT environments. He has had the opportunity to assess systems used daily by millions of people in Poland, as well as components of critical infrastructure.
He is also involved in delivering cybersecurity training, particularly related to secure working practices and compliance with requirements such as NIS2.
Analog mobile networks transmitted calls without encryption, making eavesdropping possible with nothing more than a nearby receiver, a vulnerability that drove the shift toward cryptographic standards in later generations.Overlay attacks on Android exploit legitimate app permissions to place invisible input fields over login screens, capturing banking and social media credentials without the user suspecting anything is wrong.Users accepting all app permissions without reading them, because convenience outweighs caution, is the primary mechanism attackers rely on to extract sensitive data from smartphones.Governments have requested push notification metadata from platform operators, proving that data types widely assumed to be non-sensitive can still expose user behavior and associations.Forcing older Android versions and legacy network technologies to remain supported, to serve users who cannot or do not upgrade, keeps known security weaknesses in active circulation across entire populations.More Links with Insights:
Tracking NSO Group's Pegasus SpywareThe EU's DMA Directive and "European iOS"The Dark Side of Accessibility and Overlays on AndroidGuardsquare Resource LibraryDetecting Location Spoofing