Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not openly display the security code for providers (?) #36

Open
adewes opened this issue Dec 2, 2021 · 0 comments
Open

Do not openly display the security code for providers (?) #36

adewes opened this issue Dec 2, 2021 · 0 comments
Labels
discuss Issue for discussion, do not implement yet!

Comments

@adewes
Copy link
Member

adewes commented Dec 2, 2021

Currently providers can just display the security code in the app to write it down. As this is a security risk we should maybe make this more difficult by e.g. protecting the code with a passphrase.

However, since the app currently performs regular encrypted cloud backups of the local secret data the security code or the secrets derived from it need to be present in the app, so a sophisticated adversary can simply extract them from there.

@benbender benbender added the discuss Issue for discussion, do not implement yet! label Dec 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
discuss Issue for discussion, do not implement yet!
Projects
None yet
Development

No branches or pull requests

2 participants