AltMe icon indicating copy to clipboard operation
AltMe copied to clipboard

Audit : Secret keys are stored in memory

Open ThierryThevenet opened this issue 2 years ago • 2 comments

we need to keep theh secret key in secure storage

ThierryThevenet avatar Feb 22 '23 12:02 ThierryThevenet

@hawkbee1 : Asking more information from audit company.

hawkbee1 avatar Feb 28 '23 06:02 hawkbee1

  • every wallet has "wallet state" where all crypto accounts with secret keys are stored /TalaoDAO/AltMe/lib/wallet/model/crypto_account_data.dart, class CryptoAccountData, L:13, L:23, secretKey field

  • this state updates every time when new account is created /TalaoDAO/AltMe/lib/wallet/cubit/wallet_cubit.dart, createBlockchainAccount, L:305

hawkbee1 avatar Apr 06 '23 06:04 hawkbee1