Skip to content

Update MASWE-0054.md - #199

Open
Diolor wants to merge 1 commit into
OWASP:mainfrom
Diolor:patch-1
Open

Diolor wants to merge 1 commit into
OWASP:mainfrom
Diolor:patch-1

Conversation

@Diolor

@Diolor Diolor commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

Fix device security patch

Fix device security patch
- **Verify Server-Side with Freshness**: Have the backend verify attestation tokens cryptographically, bind them to a server-issued nonce, and check timeliness before trusting them.
- **Gate Sensitive Operations on Verdicts**: Require valid attestation for high-risk API calls and degrade or deny service to unattested clients.
- **Layer with Local Checks**: Combine attestation with local environment checks (see @MASWE-0051, @MASWE-0053) for defense in depth, and assess the overall scheme against known bypasses.
- **Match the Verdict to the Operation**: Require the integrity level each operation calls for, keeping stricter signals such as a recent security patch for high-risk actions.

@cpholguera cpholguera Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you intentionally using "action" vs "operation", or should "high-risk action" be "high-risk operation"?

Should we use "request or action" as in the Android docs instead of "operation"?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes. Action is e.g. an http request to update your financial data. Operation is rather the purpose a particular action exists (the intent) and the "operational environment" the app operates (e.g. EUDIW or banking app). Makes sense?

@OWASP OWASP deleted a comment Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants