[Prev]

2.10 Privacy threats

T101-LeakBackup

Eavesdropping on backups (see CR213-Backup)

T102-Correlation

Database correlation by colluding entities (solution: do not leak correlation handles, i.e. use pseudonyms - see Architecture, Core Security Architecture, Access Credentials, Pull Model)

T103-TAIdP

IdP collects traffic analysis (and then sells or illicitly use it). Some counter measures:

T104-TADI

Disco collects traffic analysis (and then sells or illicitly use it)

T105-TA3rd

Traffic Analysis by Third Party

T106-CorrAudit

Correlation handles of audit trail will also become correlation handles.

T107-LogTokLeak

If WSC parties keeps log of User's pseudonym along with encrypted form of User's identifier at WSP, then WSC and WSP can correlate and collude using the encrypted form. However this threat is acute only between directly interacting parties. In a chain of web services calls longer than 3, the nonneiboughring parties are not in position to collude using this attack.

Current solution is to forbid logging the tokens, see CR53-DontLogTok.

T108-PhishPII

Tricking user to reveal PII through phising attack that poses a real looking web page to solicit PII. See also access version of the threat: T111-Phish.

T109-SocEngPII

Social Engineering, talking users to revealing PII. See also access version of the threat: T112-SocEng.

T1010-SnoopPII

Network eavesdropping to record PII.

T1011-KbdLogPII

Keyboard logger or other malware to record credentials.

T1012-MalwarePII

PII theft, e.g. copy private contact book, using malware.

T1013-PIITheft

Physical theft of PII.


[Prev | Next]