Close Menu
Daily View
  • Home
  • News
    • World
    • UK
    • US
  • The View
  • Sport
  • Culture
  • Lifestyle
  • Business
  • Tech
What's Hot

Proton fixes authentication bugs leaking TOTP secrets in logs

August 4, 2025

MHP completes acquisition of Spanish food giant Grupo Uvesa

August 4, 2025

Tommy Robinson arrested in connection with assault

August 4, 2025
Facebook X (Twitter) Instagram
Trending
  • Proton fixes authentication bugs leaking TOTP secrets in logs
  • MHP completes acquisition of Spanish food giant Grupo Uvesa
  • Tommy Robinson arrested in connection with assault
  • Scientists say they solved the mystery of what killed more than 5 billion sea stars
  • State Department may require visa applicants to post bond of up to $15,000 to enter the US
  • Man arrested on GBH suspect after video became visible to Tommy Robinson walking near the scene
  • John Jones revealed that he told the UFC “long ago” his plans during the ongoing Tom Aspinel superfight talk
  • Ready to crush the UK transfer record and form an unstoppable front three
  • Subscribe to Newsletter
  • Advertise with Us
  • Support Us
Facebook X (Twitter)
Daily ViewDaily View
Button
Monday, August 4
  • Home
  • News
    1. World
    2. UK
    3. US
    4. View All

    Can Syria rebuild its economy from the ashes of war?

    August 4, 2025

    Will the latest diplomacy move to end the war with Gaza work?

    August 4, 2025

    What does China need to arrest a fall in fertility rate?

    August 3, 2025

    Why America wins energy innovation

    August 3, 2025

    Tommy Robinson arrested in connection with assault

    August 4, 2025

    Man arrested on GBH suspect after video became visible to Tommy Robinson walking near the scene

    August 4, 2025

    A man and woman charged with murder at a 26-year-old in southeast London

    August 4, 2025

    Government pledges extra £100m to tackle people smuggling

    August 4, 2025

    Scientists say they solved the mystery of what killed more than 5 billion sea stars

    August 4, 2025

    State Department may require visa applicants to post bond of up to $15,000 to enter the US

    August 4, 2025

    The majority of the US has highlighted the cost of food, according to an Daily View-NORC poll.

    August 4, 2025

    Boeing workers who build fighter jets plan to go on strike

    August 4, 2025

    Tommy Robinson arrested in connection with assault

    August 4, 2025

    Scientists say they solved the mystery of what killed more than 5 billion sea stars

    August 4, 2025

    State Department may require visa applicants to post bond of up to $15,000 to enter the US

    August 4, 2025

    Man arrested on GBH suspect after video became visible to Tommy Robinson walking near the scene

    August 4, 2025
  • The View
  • Sport
  • Culture
  • Lifestyle
  • Business
  • Tech
Daily View
Home»Tech

Proton fixes authentication bugs leaking TOTP secrets in logs

August 4, 2025 Tech 3 Mins Read
Proton fixes authentication bugs leaking TOTP secrets in logs
TOTP secret passed to 'params' variable which is added to logs
Share
Facebook Twitter LinkedIn Pinterest Email

Proton mounted a bug within the new authentication app on iOS. This may report consumer delicate TOTP secrets and techniques in plain textual content and expose multifactor authentication codes if the logs are shared.

Final week, Proton launched the brand new Proton Authenticator app, a free standalone two-factor authentication (2FA) utility for Home windows, MacOS, Linux, Android, and iOS.

This app is used to retailer multifactor authentication TOTP secrets and techniques that can be utilized to generate one-time passcodes for authentication on web sites and functions.

Over the weekend, customers posted on a now-deleted Reddit publish that that they had printed TOTP’s secrets and techniques within the debug logs of apps that had iOS variations beneath. setting > log.

“I imported my 2FA account and enabled backup and sync. At first every little thing appeared good. At one level, I modify the labels with one of many entries and simply switched the app, then learn the archive of my publish.

“I’ve come again to search out that about half of the 2FA entries are gone. It might have occurred after the label modifying, however I wasn’t 100% positive. It may have been one thing else. Both means, it disappeared with none errors or warnings.”

“I needed to do the best factor and submit a bug report. Throughout preparation, I opened a log file that the app generated, once I was considerably annoying and deeply involved.

One other commenter identified that the leakage was because of the code within the iOS app (1, 2). This provides a number of information concerning the TOTP entry to the PARAMS variable and is handed to 2 features which are used so as to add or replace the TOTP secret in your app.

TOTP secrets have been passed to
TOTP secrets and techniques have been handed to “params” variables added to the log

When that is finished, the operate provides this information to the log entry and exposes the TOTP secret.

See also  Blacksuit ransomware leak site seized by operation checkmate

Proton confirmed a bug within the iOS model and stated it’s at present pinned in model 1.1.1, launched on the App Retailer about 7 hours in the past.

“Secrets and techniques usually are not despatched to the server in plain textual content, and all secret syncing is finished with end-to-end encryption. The logs are native (not despatched to the server). These secrets and techniques can be exported to the gadget to fulfill the portability necessities of GDPR information.”

“In different phrases, even when this isn’t included within the log, anybody who has entry to the gadget to retrieve these logs can get secrets and techniques. Proton encryption can’t be shielded from compromises on the a part of the gadget, so it’s outdoors the risk mannequin, so it’s all the time obligatory to guard the gadget.”

“I up to date the iOS app to vary the logging conduct, however this isn’t a vulnerability that an attacker may exploit, and if the attacker has entry to the gadget to entry the native logs, then they will get secrets and techniques anyway.

Whereas this log information can’t be exploited remotely, the priority was that if the log was shared or posted wherever to assist diagnose issues or bugs, it uncovered delicate TOTP secrets and techniques to 3rd events.

You may import these secrets and techniques into one other authentication machine and generate a one-time passcode for that account.

News Tech

Keep Reading

Tommy Robinson arrested in connection with assault

Scientists say they solved the mystery of what killed more than 5 billion sea stars

State Department may require visa applicants to post bond of up to $15,000 to enter the US

Man arrested on GBH suspect after video became visible to Tommy Robinson walking near the scene

CTM360 finds malicious “Clicktok” campaigns targeting users of Tiktok shops

The majority of the US has highlighted the cost of food, according to an Daily View-NORC poll.

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

It’s official: Marvel doesn’t know what’s wrong with himself

July 20, 2025

Chelsea discusses to sign a “exceptional” £52 million ace

July 20, 2025

Duke’s Cooper Flag declares “best decision in hindsight” for the 2025 NBA Draft

July 20, 2025

What should I do to see wildlife in a national park?

July 20, 2025
Latest Posts

Proton fixes authentication bugs leaking TOTP secrets in logs

August 4, 2025

MHP completes acquisition of Spanish food giant Grupo Uvesa

August 4, 2025

Tommy Robinson arrested in connection with assault

August 4, 2025
dailyview
Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

Topics

  • News
  • Business
  • Culture
  • Lifestyle
  • Sport

Topics

  • World
  • UK News
  • USA News
  • Tech

Pages

  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

Editors Picks

Chelsea discusses to sign a “exceptional” £52 million ace

Duke’s Cooper Flag declares “best decision in hindsight” for the 2025 NBA Draft

What should I do to see wildlife in a national park?

© 2025 All Rights reserved | Powered by Dailyview

Type above and press Enter to search. Press Esc to cancel.