Resilience (RS9)
Resilience
9
Sean can reverse engineer the app because code or security-sensitive resources (e.g., strings, configuration, and bundled assets) are insufficiently obfuscated
Scenario: Sean can reverse engineer the app because code or security-sensitive resources (e.g., strings, configuration, and bundled assets) are insufficiently obfuscated
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG Best: 0029
SAFECode™: -
MASVS: MASVS-RESILIENCE-3
No attacks registered!