Reshape OWASP Mobile Security Wiki

73 views
Skip to first unread message

Jeroen Willemsen

unread,
Jul 8, 2019, 7:34:01 AM7/8/19
to OWASP Mobile Top 10 Risks
Hi all,
the current OWASP Mobile Project wiki ( https://www.owasp.org/index.php/OWASP_Mobile_Security_Project ) contains quite some outdated project-pages and pages with hardly any metadata on versioning/age, etc. This is why I will clean it up today and more more older pages to the archive. If you have an active OWASP mobile security related project. Please let me know, so i can add links to your project as well.

With kind regards,
Jeroen Willemsen

Jeroen Willemsen

unread,
Jul 11, 2019, 3:11:47 AM7/11/19
to OWASP Mobile Top 10 Risks
Hi all,
Another small update on this subject: I have cleared up the project-page https://www.owasp.org/index.php/OWASP_Mobile_Security_Project and want to move ahead with cleaning up the remaining tabs, but for these i wonder: who is in charge of:


as we want to clean this up/update it to a better shape and/or migrate some of it towards the MASVS/MSTG. 

Given the beauty of https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=M-Threat_Model_Project  I wonder: what is the current status of that project? 
With kind regards,
Jeroen 

Elie Saad

unread,
Jul 16, 2019, 4:10:57 AM7/16/19
to OWASP Mobile Top 10 Risks
Hi Jeroen :)

It seems like the 2 most probable ones to talk to are Jim Manico and Milan Singh Thakur.
Jim can be reached through Twitter: https://twitter.com/manicode
Milan can be reached through LinkedIn: https://www.linkedin.com/in/milansinghthakur/

I am pretty sure Jim will reply, and if you want I can hit him up. I have no prior experience with Milan, so I don't know what's his activity like.

Best Regards,
Elie Saad

Jim Manico

unread,
Jul 17, 2019, 12:01:41 AM7/17/19
to Elie Saad, OWASP Mobile Top 10 Risks
Whats up how can I help?

--
Jim Manico
@Manicode
(808) 652-3805
> --
> You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
> To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/d6c10f09-0f2c-4ef3-889e-ca7f3ae3b972%40owasp.org.

Elie Saad

unread,
Jul 17, 2019, 12:23:58 AM7/17/19
to OWASP Mobile Top 10 Risks

Jim Manico

unread,
Jul 17, 2019, 11:18:37 AM7/17/19
to Elie Saad, OWASP Mobile Top 10 Risks
I dont know. Just remove then for now and list them in an “archive” section for now is my suggestion. Is that cool?

--
Jim Manico
@Manicode
(808) 652-3805

> --
> You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
> To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/a28d87e4-3115-4dd2-92fd-3bef2ff75997%40owasp.org.

Jeroen Willemsen

unread,
Jul 17, 2019, 3:22:16 PM7/17/19
to OWASP Mobile Top 10 Risks
Hi all,

Sounds like a plan! We will start that in a later stage, for now we have the following announcement:

we want to reshape https://www.owasp.org/index.php/OWASP_Mobile_Security_Project into a general overview of all the mobile security related projects even further, by giving the OWASP top 10 a new home: https://www.owasp.org/index.php/OWASP_Mobile_Top_10 . Then we will remove the "project-related" overhead a bit as well.

If anybody objects: feel free to email back and/or slack me on OWASP slack.


With warm regards,

Jeroen

On Wednesday, July 17, 2019 at 5:18:37 PM UTC+2, Jim Manico wrote:
I dont know. Just remove then for now and list them in an “archive” section for now is my suggestion. Is that cool?

--
Jim Manico
@Manicode
(808) 652-3805

> On Jul 16, 2019, at 9:23 PM, Elie Saad <> wrote:
>
> Hi Jim! Might you know who is in charge of the following mobile projects:
> - https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=Secure_M-Development
> - https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=Top_10_Mobile_Controls
> - https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=M-Threat_Model_Project
>
> Jeroen and the team are looking to clean up the Mobile Security Project.
>
> --
> You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to <>

Elie Saad

unread,
Jul 18, 2019, 2:04:14 AM7/18/19
to OWASP Mobile Top 10 Risks
I agree to the requested amendment.
One thing first though. A cleanup is a must. Having too many URLs with almost similar names is not fun for new-comers. Some examples:
https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-_Top_Ten_Mobile_Risks
https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10

There is the old mobile security project as well:
https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project

Let me know how you'd like to have the Mobile top 10 in order to assist in preparing the template.

I believe Threat Modeling can be integrated as another project as well, where it can contain how to threat model from a big picture, then have a more robust and technical explanation, and with some references to slides, videos, courses.

Jeroen Willemsen

unread,
Jul 18, 2019, 2:09:26 AM7/18/19
to OWASP Mobile Top 10 Risks, elie...@gmail.com, Harold Blankenship
Great! Regarding the too many urls, I was wondering: Harold can you help us out with this by cleaning up some of the older project materials? 

For the Mobile Top 10: I hoped to end up with a similar project page as we have for the MSTG: so with the logo, the lab-level-banner, etc, main content on the left, leaders/presentations/mailinglist on the right & an achknowledgement tab. Let's start on monday if there is no objection filed by then ;-).

Regarding the threatmodelling: I know we had quiet some concersations on OSS19 regarding picking it up again, so I hope that people will pick up the mobile threat modelling again... as i do believe that the mobile part of the threatlandscape looks quiet different from using a laptop+browser :). So cleaning it up later, could be a valid alternative to me as well.


With kind regards,
Jeroen Willemsen

Jim Manico

unread,
Jul 18, 2019, 9:51:49 AM7/18/19
to Jeroen Willemsen, OWASP Mobile Top 10 Risks, elie...@gmail.com, Harold Blankenship
Jeroen,

You’re being very smart about this. I say just charge and make it happen! :)


--
Jim Manico
@Manicode
--
You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/bfe0bd4f-c357-4973-b46d-df41f48d5a43%40owasp.org.

Jeroen Willemsen

unread,
Jul 22, 2019, 4:54:36 PM7/22/19
to OWASP Mobile Top 10 Risks
Hi Jim,
thanks!

I have updated the mobile top 10 project page to: https://www.owasp.org/index.php/OWASP_Mobile_Top_10
I have updated the mobile security project page to: https://www.owasp.org/index.php/OWASP_Mobile_Security_Project

Feel free to further update it if necessary ;-).
With kind regards,
Jeroen 
Jeroen,

To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-10-risks+unsub...@owasp.org.

Scott King

unread,
Jul 24, 2019, 10:40:04 AM7/24/19
to Jeroen Willemsen, OWASP Mobile Top 10 Risks
Jeroen,

Are you finished deleting links? Im linking to this https://www.owasp.org/index.php/OWASP_Mobile_Top_10 in a blog for next week and I don't want a dead link.

Thank for your contributions!

Regards,

Scott


Scott King  |  +1 (214) 316-0746  |  On LinkedIn  |  #MobileSecurity



Jeroen,

To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.

--
You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/c24aed1e-4269-4fa1-8fb6-4ccef1013fe5%40owasp.org.

Jeroen Willemsen

unread,
Jul 24, 2019, 11:02:25 AM7/24/19
to OWASP Mobile Top 10 Risks
Hi Scott,

this is indeed the stable link / new link for the mobile top 10 project. So that will not be deleted: you're blog is safe for a loooooong time! 
Note, the old (https://www.owasp.org/index.php/Projects/OWASP_Mobile_Security_Project_-_Top_Ten_Mobile_Risks) link is not dead either, it just redirects to the new one. Next: any missing links of old tabs at the Mobile Security page will not be dead either: they will navigate you to the home of the project, with links to active projects and archived pages.

With kind regards,
Jeroen 
Jeroen,

To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-10-risks+unsub...@owasp.org.

--
You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-10-risks+unsub...@owasp.org.

Jim Manico

unread,
Jul 28, 2019, 4:42:18 PM7/28/19
to Jeroen Willemsen, OWASP Mobile Top 10 Risks

It all looks SO CLEAN! Thank you!

- Jim

To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/c24aed1e-4269-4fa1-8fb6-4ccef1013fe5%40owasp.org.
-- 
Jim Manico
Manicode Security
https://www.manicode.com

Jeroen Willemsen

unread,
Jul 28, 2019, 11:39:04 PM7/28/19
to Jim Manico, OWASP Mobile Top 10 Risks
Thanks Jim!
And thank you Elie & Sven for helping me out to accelerate this!


With kind regards/met vriendelijke groet,
Jeroen Willemsen
Projectleader MSTG, Check it out at https://github.com/OWASP/owasp-mstg
Sent from a mobile device with autocomplete

Op zo 28 jul. 2019 22:42 schreef Jim Manico <j...@manicode.com>:
Jeroen,

To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/bfe0bd4f-c357-4973-b46d-df41f48d5a43%40owasp.org.
--
You received this message because you are subscribed to the Google Groups "OWASP Mobile Top 10 Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to owasp-mobile-top-1...@owasp.org.
To view this discussion on the web visit https://groups.google.com/a/owasp.org/d/msgid/owasp-mobile-top-10-risks/c24aed1e-4269-4fa1-8fb6-4ccef1013fe5%40owasp.org.

Milan Singh Thakur

unread,
Aug 4, 2019, 12:33:01 PM8/4/19
to Jeroen Willemsen, Jim Manico, OWASP Mobile Top 10 Risks
Reply all
Reply to author
Forward
0 new messages