Mukshith.verse
2023/05/13 07:32
The Magic SDK does contain one known security flaw, which developers have taken steps to mitigate. Because it relies on email tokens to authenticate a user, an attacker can potentially gain access to a user’s HSM by hacking into their email account and then requesting to authenticate from the attacker’s own device. Once they’ve got access to the HSM, they can authorize any transactions from the user’s account.
For this reason, both Immutable Passport and Kresus plan to use two-factor authentication (2FA) as an additional layer of security in case a user’s email account becomes compromised.
Wallets based on Magic do not have passwords, so they can’t be hacked through the usual method of stealing and cracking a password hash.

All Comments0LatestHot
No records