Tampering
Tampering is the act of interfering with or modifying something with the intent to cause damage. This could be an act of vandalism; it could be disabling a security system to gain access, as shown in Figure 3.1, or it could be modifying an identity document to gain access to a facility. Tampering comes in many shapes and sizes.
In this chapter, we will cover the different tampering threats described on the cards available in the Tampering deck in the Elevation of Privilege card game. Tampering could affect your data both at rest or in transit, the software systems you use, and the software or hardware you develop. You’ll see that these threats are often caused by design flaws relating to access control, missing integrity checks, and missing encryption both at rest and in transit.
By the end of this chapter, you should be able to identify when these flaws are present in a design and potential strategies you can use to mitigate the threat or at least reduce the...