You must log in or register to comment.
I saw how they created the SHA-1 signature string, it was something like: “THAT_PART1_STRING(35235nnASaf12) + APPTOKEN + UDID + MYPHONENUMBER + SECURITY_IMAGE_ID”
That string, i think, looks like a “pepper”. A salt is unique per user and stored in the database; that would’ve prevented this. The pepper should never be hard coded either.
Good article! At least it was patched in about a week! I feel like so many others wouldn’t take the time to address promptly.


