Skip to content

Hash stored passcode rather than encrypt for improved security #27

@tonyr59h

Description

@tonyr59h

Reported via HackerOne. (<--Team only link)

Since BuildConfig.PASSWORD_ENC_SECRET and BuildConfig.PASSWORD_SALT are hard-coded it wouldn't take much effort to reverse engineer the stored PIN while a hashed PIN would have to be brute-forced.

Note: Update README

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions