Cryptography (CRM9)
Cryptography
9
Ramsey can access protected sensitive data because cryptographic configuration (e.g. algorithm, mode, IV, nonce, or provider) is weak or incorrectly used
Scenario: Ramsey can access protected sensitive data because cryptographic configuration (e.g. algorithm, mode, IV, nonce, or provider) is weak or incorrectly used
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG: 0210,0221,0232,0309,0310,0312,0317,0350
MASTG Know: 0011
MASWE: 0007
MASVS: MASVS-CRYPTO-1,MASVS-CRYPTO-2
No attacks registered!