Technical / Infrastructure

Secure Messaging Apps – Threat Modelling Report

White and Black Round Ceiling

(In Progress)

Secure Messaging Apps

Validation Messages:

  1. Error [ignored]:
    ‘Logs’ requires at least one ‘Any’
  2. Error [ignored]:
    ‘Logs’ requires at least one ‘Any’
  3. Error [ignored]:
    ‘Source Code Database’ requires at least one ‘Any’

Secure Messaging Apps Diagram Summary:

Not Started3
Not Applicable0
Needs Investigation0
Mitigation Implemented0
Total3
Total Migrated0

Interaction: App Download

1. An adversary could trick users into downloading the app from a malicious app store
[State: Not Started]
[Priority: High]

Category:Spoofing
Description:
Justification:<no mitigation provided>

Interaction: Deploy to App Store

2. The vendor’s build service could be compromised, leading to malicious changes to the app
[State: Not Started]
[Priority: High]

Category:Tampering
Description:
Justification:<no mitigation provided>

Interaction: Request Download

3. Google and/or Apple could maliciously modify the app
[State: Not Started]
[Priority: High]

Category:Tampering
Description:
Justification:<no mitigation provided>

Source: https://www.securemessagingapps.com/threat/