Ricardo can extract data stored by the app on a stolen or decommissioned device because it does not enforce device access security policies (e.g. PIN protected locking, app-/os-version, USB debug deactivation, device encryption and rooting)
Ricardo can extract data stored by the app on a stolen or decommissioned device because it does not enforce device access security policies (e.g. PIN protected locking, app-/os-version, USB debug deactivation, device encryption and rooting)
OWASP ASVS
STORAGE-1
OWASP AppSensor
TEST-0012
CAPEC
-
SAFECODE
OWASP MASVS (2.1): STORAGE-1
OWASP MASTG (1.7): TEST-0012
Safecode: -
No attacks registered!