Soon the first version of the “OWASP Top Ten Mobile Risks” will be announced. We’re happy to see that our risk assessment of SecureSafe is already fully aligned with OWASP. For example, SecureSafe has already implemented countermeasures for all ten risks. Notably, the first risk (Insecure Data Storage) is well addressed by SecureSafe as we encrypt all data stored locally with a key that is derived directly from the user’s password and do not solely relying on the iPhone’s disk encryption mechanisms.
Advertisement