Authentication & Authorization (AAJ)
How to play?Scenario: Ade can bypass authentication because it is not enforced using a remote endpoint, or it is not based on a cryptographic primitive protected by keystore/keychain access control flags.
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: AUTH-2
OWASP MASTG: TEST-0017,TEST-0018,TEST-0064
SAFECode: 28
Attacks
No attacks registered!