7 ms·
What? It's a self-certification checklist for apps (really the cloud services behind the apps, it only has one section about the app itself and one of the items
by resfirestar 5y ago
What? It's a self-certification checklist for apps (really the cloud services behind the apps, it only has one section about the app itself and one of the items is just "provide a privacy policy"). Nothing to do with the OS or devices.
The document the post is about: https://static1.squarespace.com/static/5c6dbac1f8135a29c7fbb621/t/604aa3fa668a8e3b50630433/1615504379349/Mobile_Application_Profile.pdf https://static1.squarespace.com/static/5c6dbac1f8135a29c7fbb...
- userbinator 5y agoThe problem is that it mixed good recommendations along with user-hostile ones. I have no qualms about things like "Detect and throttle guessing attacks" and "Require authentication for remote services containing user data.", but then there's also... SE1.1 End of life notification policy is published SE1.2 Expiration Date is published Planned obolescence. AA4 Security Updates applied automatically, when product usage allows VS4 Anti-Rollback User-control and herding. "You want this feature we removed? Too bad, fuck you." SI113 Enforce x509 certificate pinning for primary services. You can't easily MITM and see what data it's exfiltrating.