4 ms·
I'm not sure where this quote came from, but I can say that the Tesla app should avoid storing the OAuth token in cleartext. Disclaimer: I work for Promon. See
by janvidar 10y ago
I'm not sure where this quote came from, but I can say that the Tesla app should avoid storing the OAuth token in cleartext.
Disclaimer: I work for Promon. See our blog post: https://promon.co/blog/ https://promon.co/blog/
- jaclaz 10y agoThe quoted text is the last sentence in the article this thread is about: http://www.bleepingcomputer.com/news/security/android-malware-used-to-hack-and-steal-a-tesla-car/ http://www.bleepingcomputer.com/news/security/android-malwar... If the Author of the bleepingcomputer.com article has misunderstood your findings and conclusions and is reporting as yours something you didn't recommend, you should let him know and ask for a correction.
- mjg59 10y ago> I can say that the Tesla app should avoid storing the OAuth token in cleartext. Why? What additional security would encrypting it with a key that's on the same device give you?