Skip to content

Clarifying recommendations on Android internal storage encryption #3077

Closed Answered by cpholguera
azabost asked this question in Q&A
Discussion options

You must be logged in to vote

Hey @azabost, first of all, thank you very much for taking the time to send us this very detailed analysis and apologies for the delay in responding.

Please note that these chapters are not necessarily meant to be recommendations (that's the work of the vulnerability and mitigation teams). They describe how things work on the platform.

However, you are right about the inconsistencies, so thank you! I think these nuances are worth noting, even in the theory chapters.

Storing unencrypted sensitive data on internal storage may or may not be a problem, depending on the threat model of the target application. As the paragraph you copied states:

  • For MASVS L1 compliance, it is sufficient to st…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by cpholguera
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants