OWASP / owasp-masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
https://mas.owasp.org/
Creative Commons Attribution Share Alike 4.0 International
2.01k stars 431 forks source link

8.9 and 8.12 are exactly the same #112

Closed gerardocanedo closed 6 years ago

gerardocanedo commented 6 years ago

It should be merged in one item.

IMO it should be inside Impede Comprehension

sushi2k commented 6 years ago

True :-)

@b-mueller: I removed 8.9, as this requirement fit's better into "Impede Comprehension". This is the requirement:

All executable files and libraries belonging to the app are either encrypted on the file level and/or important code and data segments inside the executables are encrypted or packed. Trivial static analysis does not reveal important code or data.

Commit: https://github.com/OWASP/owasp-masvs/commit/ba68e7811e762a6432ec08771c869a145e5c8376