Kyun can access data because it has been obfuscated rather than using an approved cryptographic function
Kyun can access data because it has been obfuscated rather than using an approved cryptographic function
OWASP SCP
105,133,135
OWASP ASVS
6.2.2
OWASP AppSensor
CAPEC
-
SAFECODE
21,29
There is no substitute for a proper, approved, cryptographic function where data needs to be protected at rest or in transit. Obfuscation is rarely the correct choice. Use standard-approved functions and consider all cryptographic management requirements (e.g. key creation, distribution, protection, replacement, retirement).
OWASP ASVS (4.0): 6.2.2
Capec:
OWASP SCP: 105,133,135
OWASP Appsensor:
Safecode: 21,29
No suitable mappings were found.