• TryingSomethingNew@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    I saw how they created the SHA-1 signature string, it was something like: “THAT_PART1_STRING(35235nnASaf12) + APPTOKEN + UDID + MYPHONENUMBER + SECURITY_IMAGE_ID”

    That string, i think, looks like a “pepper”. A salt is unique per user and stored in the database; that would’ve prevented this. The pepper should never be hard coded either.

  • unitedwithme@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    Good article! At least it was patched in about a week! I feel like so many others wouldn’t take the time to address promptly.