dotp icon indicating copy to clipboard operation
dotp copied to clipboard

Vulnerabilities

Open MarvinHannott opened this issue 6 years ago • 0 comments

Though the standard allows for the use of SHA-1, it shouldn't be used to generate an OTP due to the discovered collission. Google Authenticator uses SHA-256 which is secure.

Also the function for verification isn't constant time so an attacker could perform a timing-attack.

I would be happy in assisting to close those vulnerabilities.

MarvinHannott avatar Sep 10 '19 19:09 MarvinHannott