Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

This repository had a security flaw, please include latest commit #8

Open
sschiessl-bcp opened this issue Jan 21, 2019 · 6 comments
Open

Comments

@sschiessl-bcp
Copy link

Please do not use this as your code base until fixed

@sschiessl-bcp
Copy link
Author

Addressed with 5e56d52

@sschiessl-bcp sschiessl-bcp changed the title This repository has a security flaw This repository had a security flaw, please include latest commit Jan 22, 2019
@sschiessl-bcp
Copy link
Author

sschiessl-bcp commented Jan 22, 2019

This is a ping to all forks of this repository, please include latest commit and notify your customers. Please be careful with unmaintained and unaudited libraries, and do your own due dilligence.

@androidlgf
@antom487
@bc-hub
@abitmore
@btcpimp
@bxlkm
@cogutvalera
@fonero-project
@liangzb0614
@sanjumm1983
@senlinms
@shanxin
@Stevengu999
@tozzais
@UL-F
@chengang21
@cryptobot
@dot5enko
@fork-android
@fulltimegeek
@gzbin7878at2016
@HenuElvis
@jaypatel2459
@johnda
@kyanite
@Mstar7264
@NionioMoney
@preico
@fintehru
@KITAPLATFORM
@rainJohn
@slashcol
@Stanoevich
@talentdeveloper
@VELLEVET
@XBTS
@zhuhaikuan

@abitmore
Copy link

Thanks for the notification.

@abitmore
Copy link

Also pinging @chouheiwa: perhaps https://github.com/chouheiwa/bitshares_wallet is affected.

@sschiessl-bcp
Copy link
Author

Update on the provided fix, it is not sufficient.

See here
https://arstechnica.com/information-technology/2013/08/google-confirms-critical-android-crypto-flaw-used-in-5700-bitcoin-heist/

Google fixed this issue in Android in version 4.3, which is SDK version 18. The app has minSDKVersion set at 15 and is still vulnerable.

Please use this RFC6979 compliant fix below

bitshares#2

@Kwaskoff
Copy link

Thank you for your support. We have notification our users and accept bug fix.

@sschiessl-bcp sschiessl-bcp reopened this Nov 21, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants