3 ms·
I would say in comparison to storing it on the server, storing the encrypted private key in Keychain probably offers a lot more security. An attacker would need
by hazz 12y ago
I would say in comparison to storing it on the server, storing the encrypted private key in Keychain probably offers a lot more security. An attacker would need direct access to the device and would need to either a) know the user's passphrase, b) be able to fool TouchID or c) be able to bypass Keychain's security.
However if iCloud Keychain is enabled then this opens up the attack surface a lot more.