Cryptography (CRM8)
Cryptography
8
Adel can predict and use the app's cryptographic keys because they are insufficiently long and random, can be enumerated, or derived from known values
Scenario: Adel can predict and use the app's cryptographic keys because they are insufficiently long and random, can be enumerated, or derived from known values
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: CRYPTO-1
OWASP MASTG: TEST-0013,TEST-0016,TEST-0063
SAFECode: 21,29,32,33
Attacks
No attacks registered!