Closed wordeater closed 7 months ago
@wordeater Thanks for this report! I take security and privacy very seriously, so I appreciate you taking the time to provide this information. Allow me to opine on these findings and please let me know if you disagree.
kotlin.random.Random
as opposed to java.security.SecureRandom
. I will investigate the differences here.android.permission.INTERNET
permission, so it is unable to communicate with any domain.Hi @wordeater , did you happen to receive a response from Sentinel One regarding this?
I added the ability to change between the Kotlin "default" random number generator and Java's "cryptographically secure" variant in this commit. The next release I'll switch over to Android App Bundle and migrate to Google Play's signing mechanism. That should address the two main concerns for this issue.
Sentinel One detects this as Malicious but has a Low Privacy Risk and Low Security Risk. The file hash for the APK is: 04ae8a60c75e139e40ce06e347630d46 It seems to be upset about a few insecure coding practices which can you read about in the PDF. We've opened a Case with SentinelOne to try to get details on why it thinks the APK is malicious. S1-Simple Coin Flip-Technical Report.pdf