Skip to content

MASTG v1->v2 MASTG-TEST-0018: Testing Biometric Authentication (android) #2952

@cpholguera

Description

@cpholguera

Create a new MASTG v2 test covering for":

Follow the guidelines

IMPORTANT NOTE

This v1 test doesn't contain a lot of detail. See https://mas.owasp.org/MASTG/0x05f-Testing-Local-Authentication/ for more context when porting it.

Also see:

Relevant weaknesses

  • MASWE-0046 Crypto Keys Not Invalidated on New Biometric Enrollment
  • MASWE-0045 Fallback to Non-biometric Credentials Allowed for Sensitive Transactions
  • MASWE-0044 Biometric Authentication is Event-bound

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions