Skip to content

Introduce Threat model #782

Closed
Closed
@kmindi

Description

@kmindi

It would be good to know what attacks/threats were already considered in the current design and how they should be prevented. Additionally it would make sense to add those which were left out or are not considered at the moment.

Maybe this could be done in the context of a wiki page.

Threat related Issues

Uncategorized

Being forced to do something:

Traffic Analysis:

Message Security

Application

Application Locking:

Application Storage Security:

Application Runtime Security

Denial of Service

Application hiding/obfuscation

APK/Building/Packaging/Releases/Download

Dependencies (e. g. other libraries)

Authentication:

(Leak of) Personal Identifyalbe Information (PII) / Privacy:

Communicating/Showing Security related Issues

Threat Model

  • Document current security features and what attacks they should prevent
  • Create an overview about the attacks which should be prevented
  • Create security architecture diagrams
  • Introduce Tests to ensure sourcecode always matches specification for security features

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions