Skip to content

Hash stored passcode rather than encrypt for improved security #27

Description

@tonyr59h

Reported via HackerOne. (<--Team only link)

Since BuildConfig.PASSWORD_ENC_SECRET and BuildConfig.PASSWORD_SALT are hard-coded it wouldn't take much effort to reverse engineer the stored PIN while a hashed PIN would have to be brute-forced.

Note: Update README

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions