Confirmed users
717
edits
No edit summary |
No edit summary |
||
Line 17: | Line 17: | ||
Use cases for unauthenticated code: App prompts user to send SMS | Use cases for unauthenticated code: App prompts user to send SMS | ||
Authorization model for uninstalled web content: Explicit | Authorization model for uninstalled web content: Explicit via web activities | ||
Authorization model for installed web content: Explicit | Authorization model for installed web content: Explicit via web activities | ||
Potential mitigations: | Potential mitigations: | ||
== | == Privileged (approved by app store) == | ||
Use cases for | Use cases for privileged code: Full-featured SMS app. Read & send SMS. | ||
Authorization model: Explicit | Authorization model: Explicit | ||
Potential mitigations: | Potential mitigations: Set thresholds or warnings on premium numbers. Only allow sending of SMS's to user-provided contacts. Show OS confirmation of message before sending. | ||
== Certified ( | == Certified (system-critical apps) == | ||
Use cases for certified code: SMS app | Use cases for certified code: SMS app | ||