Skip to content

Threat-model delegated administration and document the privacy data flow #44

Description

@ShalomMaman

Parent epic: #41

Goal

Produce the security and privacy design that must be reviewed before Device Guard accepts any remote policy write.

Scope

Model the complete flow between the account owner/device custodian, delegated filtering administrator, read-only support, release/operator staff, web console, identity provider, management service and enrolled device.

Cover at least:

  • abusive or mistaken administrators;
  • stolen accounts and sessions;
  • malicious or cloned clients;
  • invitation theft and unauthorized ownership transfer;
  • replay, downgrade and stale-policy attacks;
  • service, signing-key or operator compromise;
  • insider access and cross-tenant data exposure;
  • denial of service, offline devices and clock manipulation;
  • compromised or replaced devices;
  • privacy abuse through excessive inventory, telemetry or audit data.

Document every collected field, purpose, legal/operational basis, retention, visibility, export and deletion behavior. The default design must exclude browsing history, message or contact content, location, screenshots, app content, local PINs, recovery codes and device credentials.

Complete the applicable Israeli privacy and accessibility review before customer deployment.

Acceptance criteria

  • Threat model identifies assets, actors, trust boundaries, entry points and mitigations.
  • A privacy data-flow diagram covers collection, processing, storage, access, export and deletion.
  • Data inventory is minimized and each retained field has a documented purpose and lifetime.
  • Cross-tenant isolation, support access and operator access are explicitly modeled.
  • Abuse cases include a malicious delegated administrator and an account-recovery attacker.
  • Residual risks and pilot blockers are recorded with owners.
  • The model is reviewed before a remote write endpoint or device apply path is enabled.

Non-goals

  • Implementing telemetry or the management service.
  • Treating a generic cloud threat model as sufficient for Device Owner policy control.

Hebrew summary

לפני פתיחת ניהול מרחוק יש למפות מי יכול לתקוף או לנצל את המערכת, איזה מידע נאסף, מי רואה אותו, לכמה זמן הוא נשמר ואיך מוחקים או מייצאים אותו. אין לאסוף תוכן אישי או קודי שחזור כברירת מחדל.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationfleetFleet operations and health visibilitypriority: P1High priorityroadmapTracked on the public production roadmapsecuritySecurity boundary or hardening work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions