mcdope / pam_usb

Hardware authentication for Linux using ordinary flash media (USB & Card based).
GNU General Public License v2.0
194 stars 20 forks source link

Security audit #55

Open mcdope opened 3 years ago

mcdope commented 3 years ago

It would be nice if someone with in-deep knowledge of PAM, and its surroundings, could review every piece of code and perform a security audit.

Would also be good in general, I would almost bet that we have some unsafe vars or pointers going to the third ring of hell or similiar.

I would be willing to pay a small amount for this out of my own pocket (contributions welcome, in case there is interest I would open a PayPal pool) to make this happen.

mcdope commented 3 years ago

Reminder for people finding this: I'm still willing to pay a bounty for an audit :money_with_wings: