edemo / PDOauth

4 stars 5 forks source link

add to attack tree: browser is hacked #866

Open magwas opened 7 years ago

magwas commented 7 years ago

if the browser is hacked (maybe through a plugin), the session cookie can be obtained or a javascript can be ran on the ui. if the user is ordinary, then it gives access to the user's data if the user is an assurer, then it may give out fake assurances