Information Disclosure
Confidentiality is often fundamental and information disclosure is when that confidentiality is compromised in some way. Your data is probably your most precious asset; that data might be personally identifiable information (PII) such as the names and addresses of your customers, it might be trade secrets such as a recipe or it could be the company’s finances. Whatever that data is, it needs to be protected adequately and, in this chapter, we look at some of the common threats in this category and how you can mitigate them.
Figure 5.1: Information being leaked
We will start this chapter by briefly looking at some key concepts around password management, key management, and cryptography. We will then cover the threats described on the cards from the Information Disclosure suit in the Elevation of Privilege card deck, including an additional two cards from the T.R.I.M. extension to the game. We’ll go through some examples...