Don’t use the Proton 2FA app, it’s logging your OTP secrets in plaintext!!
Source code
Logging params
https://github.com/protonpass/ios-authenticator/blob/main/LocalPackages/DataLayer/Sources/DataLayer/Services/EntryDataService.swift#L167-L168
Params contain secret:
https://github.com/protonpass/ios-authenticator/blob/main/LocalPackages/PresentationLayer/Sources/PresentationLayer/Pages/CreateEditEntryView/CreateEditEntryViewModel.swift#L86-L104
Login to reply
Replies (1)
