RE: RE: LeoAuth Login Method Update | Security and LocalStorage vs. Cookies
You are viewing a single comment's thread from:

RE: LeoAuth Login Method Update | Security and LocalStorage vs. Cookies

Words
491
Reading
3 min
Listen
Play
2y

One big thing I want you to understand about sending the keys over the network. Someone else having access to your keys means that they can transact as if they were you, up to the key's permission level. The highest level key that I saw leo request was active key, which has the ability to transfer funds. By transmitting the keys over the network, there are some potential issues:

  1. The obvious, Leo could purposefully store keys on their server when they get it on their server.
  2. Leo could accidentally store keys on their servers by having misconfiguration logs that are fully logging the requests.
  3. Leo uses cloudflare. Cloudflare could be storing logs of the requests which include the keys.
  4. There can be a proxy between the user and the endpoint that the user is connecting to that's logging(think workplace proxy, a lot of those even do HTTPS decryption) the requests with the keys.

This isn't a full list. While some of the work I do on a day to day basis includes security, I'm by no means a security professional.

Onto a bit of responses:

All of the solutions in this post were proactively developed and deployed.

I would call this reactive, not proactive. You made a change due to issues found by other. From what I can quickly tell, there was multiple days between initial report and Leo disabling the keys based auth from their site. I'm not fully following what's going on in MM at all times, and I'd seen the conversation happening there, but wasn't reading it entirely(I did skim it briefly afterwards though), and the first time I truly saw the issue was engrave@engrave's post on it.

There have been no security leaks of any kind.

User's keys were sent over the internet. I would say there was a security leak. Anyone who entered keys on inleo to log in using your login method SHOULD change their keys immediately. See above section for possible issues.

24 hours ago, a statement was posted in Mattermost (a platform similar to Discord where Hive devs and community members gather around various topics) which said (paraphrased) "INLEO is storing your keys on their servers".

For my particular side I never said that, only said it was a possibility of what could be happening. You guys did have other issues where you were doing that though(via cookies that louis88@louis88 pointed out in comments. Your initial response wasn't to take it seriously but to call it misleading? I don't understand where any of what I said was misleading. You were transmitting the keys to the backend.

image.png

From Khal's response to me: @khaleelkazi/re-rishi556-sslryp

Here's your own sentence with the highlighted part that you did. Which is a lie.

I'm going to be honest. I will have an insanely hard time trusting any leo product on the security side after this. Multiple trusted devs were pointing out the issue and you chose to say this instead.

@rishi556: One big thing | Ecency