Closed commjoen closed 5 years ago
] 9. MSTG: Update how we cover app-device identification: Covered in the mstg wrongly: MSTG‑STORAGE‑10: https://github.com/OWASP/owasp-mstg/blob/4d9938a3d767f56387fb2586886664aab89419e6/Document/0x04e-Testing-Authentication-and-Session-Management.md#testing-login-activity-and-device-blocking-mstgauth11, but we do cover instanceID and identifierforVendor in different pages. Let;s make sure we open up an issue where verification is set straight with modern standards & create a requirement for V6 as jotted down by Sven
Fixed in #1412
Check the MSTG and make sure we only identify using : https://developer.apple.com/documentation/uikit/uidevice/1620059-identifierforvendor
See https://developer.apple.com/documentation/devicecheck as well