Picture of the author

Mukshith.verse

2023/05/13 07:32

Security concerns with Magic

The Magic SDK does contain one known security flaw, which developers have taken steps to mitigate. Because it relies on email tokens to authenticate a user, an attacker can potentially gain access to a user’s HSM by hacking into their email account and then requesting to authenticate from the attacker’s own device. Once they’ve got access to the HSM, they can authorize any transactions from the user’s account.

For this reason, both Immutable Passport and Kresus plan to use two-factor authentication (2FA) as an additional layer of security in case a user’s email account becomes compromised.

Wallets based on Magic do not have passwords, so they can’t be hacked through the usual method of stealing and cracking a password hash.

IMG-20230510-WA0031.jpg

#HTX Talks#Pizza Carnival: Share Up to 1,000 USDT!#Money hack: Soaring crypto
16Share

All Comments0LatestHot

LatestHot
noContent

No records