Mathew Solnik
Security researcher, engineering leader, and CISO. Twenty years across AI, mobile, cellular, blockchain, and embedded systems — building enterprise security programs and publishing original research.
Selected work, made public.
The first public deep technical analysis of Apple's Secure Enclave Processor (SEP) and SEPOS — the hardware-isolated security coprocessor deployed in every iPhone since the 5S. Covered SEP hardware design, boot process, SEPOS kernel and architecture, the iOS-to-SEP mailbox protocol, and the SEP attack surface — establishing the public baseline for SEP security research.
A critical set of over-the-air cellular vulnerabilities affecting devices across every major mobile platform. Developed OTA exploits including a full remote iOS jailbreak, a blind Android lock-screen bypass, and complete remote code execution on Android.
Research into “enterprise class” Android applications and “secure containers” — products widely marketed to protect sensitive corporate information on mobile devices. Covered the threat model for Android in the enterprise, what secure containers actually defended against, and assessment techniques for evaluating these vendors against real-world threats.
Remote compromise of an automotive system over the air; followed in 2013 with OTA automotive vulnerabilities enabling remote manipulation and stopping of a moving vehicle.
Where the work has happened.
Patents & applications.
Selected writing.
Coverage & recognition.
- Wired — Hackers Can Control Your Phone Using a Tool That’s Already Built Into It
- The Wall Street Journal — Smartphones Become Next Frontier in Cybersecurity
- Reuters — Smartphone Management Flaws Put Users at Risk, Researchers Say
- MIT Technology Review — Most Smartphones Come With a Poorly Secured Back Door
- CBS News — Theft via text: Cars vulnerable to hack attacks
- Vice — We Drove a Car While It Was Being Hacked
- Ars Technica — Blackphone Goes to DEF CON and Gets Hacked… Sort Of
- The Register — Two Billion Mobes Easily Hacked by Evil Base Stations
- SC Magazine — Hidden Controls Open 2 Billion Mobile Devices to Exploitation
- Dark Reading — Black Hat USA 2014: Focus on Mobile
- Android Security Acknowledgements
- Qualcomm Product Security Hall of Fame
- CERT/CC Advisory CA-2002-30