Skip to content

Conversation

@sushi2k
Copy link
Collaborator

@sushi2k sushi2k commented Sep 10, 2025

This PR closes #38

@sushi2k sushi2k changed the title draft MASWE-0100 Add MASWE-0100 - Device Attestation Sep 12, 2025
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment on lines +39 to +44
To summarize:

- **Device attestation** confirms the environment is trustworthy.
- **App attestation** confirms the app instance is trustworthy.

If the app doesn't use attestation APIs or services the backend cannot ensure requests originate from a genuine app binary and from a trusted platform.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd not "summarize" here, prefer to make it more explicit above, e.g., using the bullet points.

@Diolor Diolor self-requested a review September 26, 2025 15:38
@@ -1,2 +1,2 @@
---
title: Device Attestation Not Implemented
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See https://github.com/OWASP/mastg/issues/3503#issuecomment-3477881489

Suggested change
title: Missing or Incorrect Device Attestation

Co-authored-by: Carlos Holguera <perezholguera@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[MASWE-0100] New MASWE Weakness

4 participants