Cornucopia (CM4)
Cornucopia
4
Elizabeth can reduce app users' privacy because the app sends too much personal data without the user's consent to downstream services that are outside the user's control
Scenario: Elizabeth can reduce app users' privacy because the app sends too much personal data without the user's consent to downstream services that are outside the user's control
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: PRIVACY-1
OWASP MASTG: -
CAPEC: 410
SAFECode: -
Attacks
No attacks registered!