3 ms·
It's not just that, many of the custom implementations of Google Authenticator keep the seed in plaintext.
by webhat 12y ago
It's not just that, many of the custom implementations of Google Authenticator keep the seed in plaintext.
- akerl_ 12y agoThat doesn't bother me terribly much. Passcode or not, I pretty much consider everything on my phone to be unencrypted, and treat it as such. Sandboxing the app from other apps matters much more. If somebody gets access to my phone, either by rooting it over the network or physically, I'm gonna consider that token burned and generate a new one.
- webhat 12y agoIt didn't bother me either, I'm the one he had the conversation with, until I realized that the phone isn't the problem. It's people using implementations like this: http://gauth.apps.gbraad.nl/ http://gauth.apps.gbraad.nl/