SrsSec / SrsPass-pwa

A secure deterministic password generator with properties resulting in a statelessly capable password manager
https://app.srspass.com
GNU Affero General Public License v3.0
5 stars 1 forks source link

feat: authentication mechanism for seed #5

Closed D-Nice closed 3 years ago

D-Nice commented 3 years ago

Research (Both security implication-wise and end-user), if AES-GCM alone is sufficient as an auth guarantee for the seed phrase (that someone didn't maliciously change the seed phrase):

blocked by https://github.com/SrsSec/SrsPass-pwa/issues/3 needing stores implementation first

D-Nice commented 3 years ago

2,3 will go to mvp 0.3 milestone in separate issue

D-Nice commented 3 years ago

closed by https://github.com/SrsSec/SrsPass-pwa/commit/159f297b8b0cf8e48cbc74126f0f7aa94426306b#diff-6f0eb39b514a42780ab1a59580bfdf290010ceebbce313c08125b16a741bbb85R95