Side Event
Breaking trust: Internal desktop apps and the AppStream illusion
Thursday 05, 10:00h - 11:00h
| Level 0 - Room 2.1
Public Access
2026-11-05 10:00
2026-11-05 11:00
Europe/Madrid
Breaking trust: Internal desktop apps and the AppStream illusion
Desktop applications have fallen out of the spotlight in the AI era, yet they remain deeply embedded in the internal infrastructure of countless companies and research labs, often running with elevated trust and minimal scrutiny.
This talk examines the security posture of desktop applications through the lens of Tier2 vs. Tier3 architectures, breaking down the structural weaknesses inherent to each model. Through real-world case studies, we'll walk through practical exploitation of common vulnerability classes (including login bypass, authentication bypass, and insecure deserialization), demonstrating how these flaws are found and abused in production environments.
We'll then examine standard remediation strategies for these vulnerabilities and discuss their inherent limitations. Finally, we'll dig into a widely adopted mitigation pattern: using application virtualization platforms like AppStream or Citrix to "convert" a Tier2 application into a Tier3-equivalent deployment.
We'll critically assess whether this approach constitutes a genuine architectural fix. Spoiler: it doesn't always hold up, and we'll show how it can be bypassed.
Level 0 - Room 2.1
Desktop applications have fallen out of the spotlight in the AI era, yet they remain deeply embedded in the internal infrastructure of countless companies and research labs, often running with elevated trust and minimal scrutiny.
This talk examines the security posture of desktop applications through the lens of Tier2 vs. Tier3 architectures, breaking down the structural weaknesses inherent to each model. Through real-world case studies, we'll walk through practical exploitation of common vulnerability classes (including login bypass, authentication bypass, and insecure deserialization), demonstrating how these flaws are found and abused in production environments.
We'll then examine standard remediation strategies for these vulnerabilities and discuss their inherent limitations. Finally, we'll dig into a widely adopted mitigation pattern: using application virtualization platforms like AppStream or Citrix to "convert" a Tier2 application into a Tier3-equivalent deployment.
We'll critically assess whether this approach constitutes a genuine architectural fix. Spoiler: it doesn't always hold up, and we'll show how it can be bypassed.