Network & Storage (NS6)
Network & Storage
6
Ricardo can extract data stored by the app on a stolen or decommissioned device because it does not enforce device access security policies (e.g. PIN protected locking, app-/os-version, USB debug deactivation, device encryption and rooting)
Scenario: Ricardo can extract data stored by the app on a stolen or decommissioned device because it does not enforce device access security policies (e.g. PIN protected locking, app-/os-version, USB debug deactivation, device encryption and rooting)
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG Best: -
MASWE: 0017
SAFECode™: -
MASVS: MASVS-CRYPTO-2
No attacks registered!