I saw how they created the SHA-1 signature string, it was something like: “THAT_PART1_STRING(35235nnASaf12) + APPTOKEN + UDID + MYPHONENUMBER + SECURITY_IMAGE_ID”
That string, i think, looks like a “pepper”. A salt is unique per user and stored in the database; that would’ve prevented this. The pepper should never be hard coded either.
That string, i think, looks like a “pepper”. A salt is unique per user and stored in the database; that would’ve prevented this. The pepper should never be hard coded either.