Open zmxv opened 2 years ago
Security
A user can try passcodes without rate limits.
Rate limiting (with exponential backoff) should be enforced to prevent brute force attack. And passcode should not be limited to four digits only.
High
Desktop (please complete the following information):
OS: [e.g. iOS] Browser [e.g. chrome, safari] Version [e.g. 22] Smartphone (please complete the following information):
Device: iPhone 13 Pro OS: iOS 15.6.1 Browser: Mobile Safari Version: Tonkeeper 2.6
No response
Hi, the issue have been registered in our system with internal TK-799. You will get a PR number when it will be fixed. Thanks!
Bug Type
Security
Reproduction steps
Actual result
A user can try passcodes without rate limits.
Expected result
Rate limiting (with exponential backoff) should be enforced to prevent brute force attack. And passcode should not be limited to four digits only.
Suggested Severity
High
Device
Desktop (please complete the following information):
OS: [e.g. iOS] Browser [e.g. chrome, safari] Version [e.g. 22] Smartphone (please complete the following information):
Device: iPhone 13 Pro OS: iOS 15.6.1 Browser: Mobile Safari Version: Tonkeeper 2.6
Additional Context
No response