Skip to content

Do not openly display the security code for providers (?) #36

@adewes

Description

@adewes

Currently providers can just display the security code in the app to write it down. As this is a security risk we should maybe make this more difficult by e.g. protecting the code with a passphrase.

However, since the app currently performs regular encrypted cloud backups of the local secret data the security code or the secrets derived from it need to be present in the app, so a sophisticated adversary can simply extract them from there.

Metadata

Metadata

Assignees

No one assigned

    Labels

    discussIssue for discussion, do not implement yet!

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions