defuse / php-encryption

Simple Encryption in PHP.
MIT License
3.78k stars 308 forks source link

Idea for a third threat model example #527

Open hirasso opened 1 month ago

hirasso commented 1 month ago

As I was reading through the two scenarios described in the Tutorial, I had a strong feeling that one important threat model was not covered: Myself as a developer! The threat model goes like this:

This is the scenario I find the most likely for many simpler websites. Data theft. Maybe you find this a useful addition to the scenarios? It's not so much about implementation but more about realizing a threat even exists.