Application development
Pages
Page 15 of 16
Questions for application developers
For anyone procuring an application built by a third party, you can ask developers the example questions below. Their answers will help you gain more (or less) confidence about the security of their products.
The most thorough way to assess an application before deploying it would be to conduct a full source code review to ensure it meets the security recommendations and contains no malicious or unwanted functionality. Unfortunately, for the majority of third party applications, this will be infeasible or impossible. However, the responses from the third party should help provide confidence that the application is well written and likely to protect information properly.
2.1 Secure data storage
The following questions will help you gain confidence that a UWP application stores sensitive data in a secure manner:
| Questions | What to look for in answers |
|---|---|
| What is the flow of data through the application - source(s), storage, processing, and transmission? | Answers should cover all forms of input including data entered by the user, network requests, and inter-process communication. |
| How is sensitive data stored on the device? | Data should be stored in a location that cannot be accessed by other applications on the device. Data should not be accessible to other applications on the device through inter-process communication provided by the application, with the following exceptions:
Data should be encrypted when stored on the device. Encryption of sensitive data should be performed with a key stored either using TPM or on a remote server, as documented in section 1.4 of Secure Windows application development. |
| What device or user credentials are being stored? Are these stored in the Credential Locker? | User credentials should be encrypted and stored using Credential Locker. |
| Are cloud services used by the app? What data is stored there? How is it protected in transit? | Data in transit to cloud services should be protected using appropriate encryption. |
2.2 Secure data transmission
The following question will help you gain confidence that a UWP application transmits sensitive data securely:
| Questions | What to look for in answers |
|---|---|
| Is transmitted and received data protected by cryptographic means, using well-defined protocols? If not, why not? | Mutually authenticated TLS, Secure Chorus, or other mutually authenticated secure transport should be used to protect information as it travels between the device and other resources. This should be answered specifically for each service the application communicates with to send and receive sensitive information. |
2.3 IPC mechanisms
The following question will help you gain confidence that a UWP application shares sensitive data securely:
| Questions | What to look for in answers |
|---|---|
Are any UWP Share contracts, Universal Links, or other inter-process data sharing procedures declared or handled by the application? What actions can these invoke? | M Answers should cover any instances of use and suitably explain how and why they are used, rather than a 'yes' or 'no' reply. Any inability to explain rationale should be taken as concern about the application. |
Can other applications cause the application to perform a malicious action or request on its behalf? | Interactions with other applications should be limited to only those essential for the application to function. |
2.4 Binary protection
The following questions will help you gain confidence that a UWP application protects its data within a binary:
| Questions | What to look for in answers |
|---|---|
| Is the application compiled in release mode and has all debug information been removed from the binary? | All debugging information should have been removed from the application. |
| If there is potential for loss of sensitive data as a result of an attacker fully understanding the workings of the application, does the application make use of obfuscated code or other protections against reverse engineering? | Code obfuscation should be used to help hinder reverse engineering of applications. |
Is the application digitally signed by either the store or a trusted certificate? Are signature verifications in place for tamper detection? | These protections improve the security of the application, if they are not used reasons should be given to suitably explain why. |
2.5 Server side controls
The following questions will help you gain confidence that a UWP application protects its data on the server side:
| Questions | What to look for in answers |
|---|---|
If the application connects to remote services to access sensitive data, how can that access be revoked? How long does that revocation take? | Assessors should be aware of the length of window of opportunity for data theft. |


