Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cryptographic APIs misuses #248

Open
misterAnderson90 opened this issue Dec 17, 2021 · 4 comments
Open

Cryptographic APIs misuses #248

misterAnderson90 opened this issue Dec 17, 2021 · 4 comments

Comments

@misterAnderson90
Copy link

I'm a PhD student interested in finding security vulnerabilities in open source projects.

We found one warning (indicating potential vulnerabilities) when running the CogniCrypt static analyzer (*) on encounter-wallet-flutter (or its library dependencies). We documented this issue in a private gist for the sake of confidentiality (non-disclosure).

Can you please let us know whether we can share these gists with you? We are eager to evaluate the perception of developers (e.g. severity of these warnings) and improve encounter-wallet-flutter's security, and the quality of the reports of static analysis tools.

(*) https://github.com/CROSSINGTUD/CryptoAnalysis

@brenzi
Copy link
Member

brenzi commented Dec 19, 2021

Thank you for reporting this. plz share your gist with me and @clangenb

@misterAnderson90
Copy link
Author

Hello @brenzi and @clangenb

Could you please send me your email addresses to share the gists? I couldn't find a way to share private gists with you. If you prefer, I can share them here.

@brenzi
Copy link
Member

brenzi commented Jan 20, 2022

please feel free to share the gist publicly here. We still have time to fix it before production use

@misterAnderson90
Copy link
Author

Hello @brenzi and @clangenb,

I'm sharing with you the documented gist. Due to code obfuscation, I couldn't find the class and method with the problem. I tried to assemble the debug version of the app but it didn't work for me.

Gist - MessageDigest

I hope this warning could be helpful for you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants