Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add MASWE-PRIVACY Weaknesses #2860

Merged
merged 29 commits into from
Oct 30, 2024
Merged

Conversation

annab-google
Copy link
Contributor

@annab-google annab-google commented Aug 2, 2024

This PR introduces new weaknesses to the OWASP MASWE, specifically focusing on privacy-related vulnerabilities such as lack of anonymization/pseudonymization, improper use of unique identifiers for tracking, inadequate privacy policies, and incomplete data collection declarations.

@annab-google annab-google changed the title Add (5) MASVS-PRIVACY Add (5) MASWE-PRIVACY Aug 2, 2024
@annab-google
Copy link
Contributor Author

Hi @cpholguera, please see Privacy weakness by Google` WG.

@cpholguera
Copy link
Collaborator

This is awesome, we'll review this soon!

Thanks a lot @annab-google and to the whole WG!

spelling fix
Copy link
Collaborator

@TheDauntless TheDauntless left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly grammar changes, apart from the copy-paste issue.

weaknesses/MASVS-PRIVACY/MASWE-0109.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0109.md Outdated Show resolved Hide resolved
@annab-google
Copy link
Contributor Author

Addressed comments.

Copy link
Collaborator

@sushi2k sushi2k left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you @annab-google ! This is a really great contribution. I've got a few small things, please have a look.

weaknesses/MASVS-PRIVACY/MASWE-0109.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0111.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0112.md Outdated Show resolved Hide resolved
@annab-google
Copy link
Contributor Author

Thank you for review @TheDauntless and @sushi2k! Let me know if anything else is pending.

weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0110.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
weaknesses/MASVS-PRIVACY/MASWE-0113.md Outdated Show resolved Hide resolved
@cpholguera cpholguera changed the title Add (5) MASWE-PRIVACY Add MASWE-PRIVACY Weaknesses Oct 21, 2024
@cpholguera cpholguera merged commit d39f267 into OWASP:master Oct 30, 2024
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants