You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Create a new risk for "Insecure Random Usage (MASVS-CRYPTO-1)" using the following information:
Using a non-cryptographically secure PRNG in a security context, such as authentication, poses significant risks. An attacker could potentially guess the generated numbers and gain access to privileged data or functionality. Predicting or regenerating random numbers can lead to encryption breaches, compromise sensitive user information, or enable user impersonation.
Create "risks/MASVS-CRYPTO/1-***-****/insecure-random/risk.md" including the following content:
If the risk has a MASVS v1 ID, you can use it to search for related tests in the MASTG and use them as input to define your risks and associated tests.
Hi @sk3l10x1ng I just noticed that we actually have this one already (we created it as part of #2518). It'd be nice if you could review it and propose changes and corrections if you have any.
I'll close this ticket but if you want I can assign you this one:
Hi @sk3l10x1ng I just noticed that we actually have this one already (we created it as part of #2518). It'd be nice if you could review it and propose changes and corrections if you have any.
I'll close this ticket but if you want I can assign you this one:
Description
Create a new risk for "Insecure Random Usage (MASVS-CRYPTO-1)" using the following information:
Using a non-cryptographically secure PRNG in a security context, such as authentication, poses significant risks. An attacker could potentially guess the generated numbers and gain access to privileged data or functionality. Predicting or regenerating random numbers can lead to encryption breaches, compromise sensitive user information, or enable user impersonation.
Create "
risks/MASVS-CRYPTO/1-***-****/insecure-random/risk.md
" including the following content:To complete the sections follow the guidelines from Writing MASTG Risks & Tests
Use at least the following references:
MASTG v1 Refactoring:
If the risk has a MASVS v1 ID, you can use it to search for related tests in the MASTG and use them as input to define your risks and associated tests.
Acceptance Criteria
risks/MASVS-CRYPTO/1-***-****/insecure-random/risk.md
)The text was updated successfully, but these errors were encountered: