V10.2 requirements - cleanup #1468
Labels
4b Major-rework
These issues need to be part of a full chapter rework
josh/elar
V10
_5.0 - prep
This needs to be addressed to prepare 5.0
parent/related issue: #1383
"V10.2 Malicious Code Search" requirements.
and third party librariesdo not contain unauthorized phone home or data collection capabilities. Where such functionality exists, obtain the user's permission for it to operate before collecting any data.and third party librariesdo not contain back doors, such as hard-coded or additional undocumented accounts or keys, code obfuscation, undocumented binary blobs, rootkits, or anti-debugging, insecure debugging features, or otherwise out of date, insecure, or hidden functionality that could be used maliciously if discovered.and third party librariesdo not contain time bombs by searching for date and time related functions.and third party librariesdo not contain malicious code, such as salami attacks, logic bypasses, or logic bombs.and third party librariesdo not contain Easter eggs or any other potentially unwanted functionality.All the "third party libraries" points should be covered by requirements:
Or is the message here, that with Level 3 you need to test and code review all used frameworks and components?
Other comments:
There are some points to keep, but a some abstraction and cleanup is needed.
The text was updated successfully, but these errors were encountered: