This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Top 10 2014-I5 Privacy Concerns

From OWASP
Revision as of 20:36, 29 June 2014 by Craig Smith (talk | contribs)

Jump to: navigation, search
Back To The Internet of Things Top 10
Threat Agents Attack Vectors Security Weakness Technical Impacts Business Impacts
Application Specific Exploitability
EASY
Prevalence
COMMON
Detectability
AVERAGE
Impact
SEVERE
Application / Business Specific
Consider anyone who has access to the device itself, the network the device is connected to, the mobile application and the cloud connection including external and internal users. Attacker uses multiple vectors such as insufficient authentication, lack of transport encryption or insecure network services to view personal data which is not being properly protected or is being collected unnecessarily. Attack could come from external or internal users. Privacy concerns generated by the collection of personal data in addition to the lack proper protection of that data is prevalent. Privacy concerns are easy to discover by simply reviewing the data that is being collected as on sets up and activates these devices. Automated tools can also look for specific patterns of data that may indicate collection of personal data. Collection of personal data along with a lack of protection of that data can lead to compromise of a user's personal data. Consider the business impact of personal data that is collected unnecessarily or isn't protected properly. Data could be stolen or modified. Could your users be harmed by having their personal data exposed?
Does My Device Present Privacy Concerns?

The most efficient way to determine if privacy concerns are present is to identify all data types that are being collected by the device, its mobile app and any cloud interfaces. The device and it's various components should only collect what is necessary to perform its function. In most cases, personally identifiable information is considered to be exposed when not properly encrypted while at rest on storage mediums and during transit over networks.

How Do I Use Prevent Privacy Concerns?

Ensuring the device minimizes privacy concerns requires:

  1. Ensuring only data critical to the functionality of the device is collected.
  2. Ensuring any data collected is properly protected with encryption.
  3. Ensuring the device and all of its components properly protected personal data.
Example Attack Scenarios

Scenario #1: Collection of personal data.

Date of birth, home address, phone number, etc.

Scenario #2: Collection of financial and/or health information.

Credit card data and bank account information.

In the cases above, exposure of any of the data examples could lead to identity theft or compromise of bank accounts.


References

OWASP

External