-
Notifications
You must be signed in to change notification settings - Fork 41
Closed
Labels
content/semanticChanges to the semantic content of the SSVC documentationChanges to the semantic content of the SSVC documentationenhancementNew feature or requestNew feature or request
Milestone
Description
In the Scope section, document the question about "who's security policies do we care about" sort of thing. The user may not be violating their own (implicit) security policy if they jailbreak their own phone. But the kernel vul they use certainly violates the kernel's security policy. Recommend avoiding anything where we need to have evidence of whether the person doing so has an "attacker-like" state of mind, if for no other reason than it's impossible to gather evidence for. So in this case, the jailbreak method is, or at least contains and uses, a vul.
Metadata
Metadata
Assignees
Labels
content/semanticChanges to the semantic content of the SSVC documentationChanges to the semantic content of the SSVC documentationenhancementNew feature or requestNew feature or request