In Proton Authenticator for iOS, secret keys have been found to be leaking into the debug log.

In the Proton Authenticator application presented last week, used for authentication with one-time passwords, a privacy issue was identified — the detailed debug log was left enabled in the builds for the iOS mobile platform, where the original secret keys for generating one-time passwords were saved in plaintext. Such a log nullified the encryption of keys and the restriction of access to them via PIN codes or biometric authentication. The issue has been resolved in update 1.1.1. In the Android builds, only the key identifier was saved in the log, not the key itself.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster