This week on Absolute AppSec 334th episode, sponsored by guardsquare.com, Seth (@sethlaw) and Ken (@cktricky) are finally sitting down with Ryan Lloyd. To find this episode, head over to absoluteappsec.com, or find us wherever you get your podcasts (and leave us a review!). If you want to catch us outside of 9am Pacific/12pm Eastern— we’re gonna be in London this winter for Black Hat Europe. Come catch our AI-Enhanced AppSec training on December 7th and 8th. 

“Because sometimes what [customers] want isn’t really what they need. […] customers will ask for one thing because they think they’ve diagnosed the symptom or the need. I always find if you scratch that surface and pull that thread more, you’ll get to the root of what problem really exists.

Ryan

Ryan Lloyd, chief product officer at GuardSquare, walked Seth and Ken through a roughly twenty-five-year path from software developer to product leader, passing through MKS, SmartBear, and Veracode before landing at GuardSquare. Five years ago, the company had about seventy employees and fifteen million dollars in annual revenue. It has since grown to two hundred employees and two-and-a-half to three times that revenue. Ryan's role splits between setting product strategy and running a security research team that studies attacker behavior. Much of the conversation centered on the tension between product and engineering visions, which Ryan called healthy tension rather than dysfunction. Ken pushed hard on how a company balances building what customers ask for against building what they will need later, calling that the hardest friction to reconcile. Ryan explained that prioritization is less a formula than a reflection of company beliefs, shaped by customer conversations, primary security research into attacker motivations, and a pragmatic marketing mantra he still quotes, that your opinion, although interesting, is irrelevant. He also offered a counterintuitive lesson: a great product matters less than people assume, since customers mostly want stability and reliability rather than a roadmap pitch.

“Any good security product company is going to have a research arm, not just […] trying to advertise. […] We need to know what the new attacks and avenues and research is to stay on top of it, to make sure that our product is still relevant.”

Ryan

Ryan traced GuardSquare's origins to ProGuard, an open source tool built to shrink and optimize Java and Android code by renaming classes and methods down to single letters, saving space and speeding startup. It was bundled into the Android developer kit and later succeeded by Google's R8 tool, which reuses ProGuard's syntax. Researchers, including Ken, who recalled parsing renamed methods and mapping files during early Android assessments, noticed that this renaming made reverse engineering harder. GuardSquare commercialized that insight as DexGuard for Android, later followed by iXGuard for iOS, layering in control flow flattening, class and string encryption, and runtime checks that detect debuggers, rooted or jailbroken devices, and hooking tools like Frida. A defining feature Ryan described is polymorphism: the obfuscation and injected checks shift with every build, so an attacker's month of reverse engineering becomes worthless the next release. His philosophy was blunt: you cannot stop reverse engineering, only raise the cost until it deters the activity. Seth compared this to polymorphic computer viruses. Platform differences matter too, since iOS never needed a shrinking tool, and Android's more open accessibility APIs create abuse paths, like fake screen readers logging taps, that iOS does not expose.

“Always a bridesmaid, never a bride. That’s kind of the role of mobile app security.”

Ryan

Seth raised a concern that mobile app security attention has faded over the past four or five years, even though daily life runs almost entirely through apps, from food delivery to home alarm systems. He noted that mobile assessments have dropped off in his consulting work, crowded out by web apps, APIs, infrastructure as code, and lately AI-related reviews. Ken agreed, saying mobile rarely shows up in client trial engagements compared to web and backend work. Ryan offered a framing, that mobile security is always a bridesmaid and never a bride, overshadowed by headline topics like cloud data breaches and ransomware. Even so, he argued the threat model has grown more sophisticated as apps do more, pointing to account takeovers targeting loyalty rewards and delivery drivers tampering with gig apps to grab extra orders. Financial services led adoption early due to regulation, and that need has since spread into other industries. On AI, Ryan was reassuring rather than alarmed, arguing that AI is not introducing new attack categories, only accelerating familiar ones, which forces defenders to move faster. Seth and Ken both agree that AI is compressing timelines industry-wide, and expect mobile security to be pulled along by that same accelerated pace.

Think about your mobile app’s source code. Once it hits the app store, it’s out in the wild. And without the right protection, decompiling is easy for malicious actors looking to steal your IP or tamper with your software.

That’s where Guardsquare comes in. Guardsquare provides the highest level of mobile app security for Android and iOS applications and SDKs. Their advanced tools integrate seamlessly into your CI/CD pipeline. We're talking polymorphic multi-layered code hardening techniques and automated runtime application self-protection, paired with mobile application security testing and real-time threat monitoring, to deliver the highest level of mobile app security without compromise.

Don't leave your hard work exposed. Secure your mobile applications today. Go to guardsquare.com to learn more.

Neiiiighhh. You can find it here:

* Unicorn sounds *

If you’re looking for a community, come join us on our Slack!

Stay Secure,

Seth & Ken

Episode 299 — Startup Grind, Will Security Companies Disappear — Ken and Seth dig into startup culture, the AI-driven security startup hype cycle, and the historical pattern of security companies getting acquired and eventually fading out. This aligns closely with Ryan’s point that enduring companies are built on customer retention and reliability, not chasing trending features. 

Episode 315 — Risks of ‘AI-Native’ Security Products, Rapid Software Development — Dives into the risks of security products being built by AI companies without deep security expertise, and argues traditional AppSec review processes are too slow for AI-speed development. 

Episode 321 — The Future of AppSec — Seth and Ken debate whether core AppSec fundamentals still hold up as AI and automation reshape the field, arguing that while manual coding fades, human judgment and auditing skills become more essential.

Absolute AppSec Happenings

We discovered a Ruby account takeover; Rogue OpenAI Agents exploited it 2 months prior — Truffle Security found a RubyGems API caching flaw that leaked authenticated users' API keys to unauthenticated requests within a one-hour CDN window; RubyGems patched it within three days of the July 2026 report. Oddly, six malicious packages exploiting that same flaw had been published 55 days earlier, with code comments referencing "leaked keys," suggesting rogue AI agents may have discovered and weaponized the bug before researchers did.

Astra for Coding: Why Are We Doing This Again? — Armin Ronacher argues OpenAI's new long-horizon model ("Astra," widely assumed to be GPT-6) is impressive but increasingly poor for software engineering. It optimizes for token efficiency and task completion over readable, maintainable code, producing code-golf-style hacks. Left unsupervised, it ran 35 hours, burned $1,200, and generated 75,000 uncommittable lines. He concludes these models may now serve other professions better than programmers.

“[…] the code mentioned in that article, and what we see also, is AI writing nonsensical function names, code that definitely does not observe blessed patterns, duplicates work, and produces thousands and thousands of lines of code that are functionally difficult for a human to either read or know what is going on.

it’s like, if they produced the insane unreadable garbage, then its really only for them to read”

Ken, in our Slack

Anthropic’s Misuse Report, Condensed to 117 Findings — Let’s be honest, I don’t have time to read the full threat intelligence report, and neither do you. Here’s a great summary from Daniel Miessler.

Upcoming Events

Where in the world are Seth and Ken?

SaintCon - October 27-30, 2026 - AppSec Community, Speaking - https://saintcon.org/

Black Hat Europe 2026 - December 7-8, 2026 - AI-Enhanced AppSec: Black Hat Edition - https://blackhat.com/