Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security question #1

Open
k06a opened this issue Apr 18, 2024 · 3 comments
Open

Security question #1

k06a opened this issue Apr 18, 2024 · 3 comments

Comments

@k06a
Copy link

k06a commented Apr 18, 2024

What would prevent anyone to compute code off-chain by calling generate method?
https://github.com/0x2fa-org/0x2fa/blob/10d3d5ed264f26dcd3b23db96fc990b73e1680c2/contracts/TOTP.sol#L100-L106

@k06a
Copy link
Author

k06a commented Apr 18, 2024

Is this method even for on-chain use?

@ahmedhamedaly
Copy link
Member

You're right, it's possible to brute-force this given the domain and sender.

@ahmedhamedaly
Copy link
Member

There will be revamp of the project soon to get rid of some pretty nasty bugs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants