• Good article! At least it was patched in about a week! I feel like so many others wouldn’t take the time to address promptly.

  • I saw how they created the SHA-1 signature string, it was something like: “THAT_PART1_STRING(35235nnASaf12) + APPTOKEN + UDID + MYPHONENUMBER + SECURITY_IMAGE_ID”

    That string, i think, looks like a “pepper”. A salt is unique per user and stored in the database; that would’ve prevented this. The pepper should never be hard coded either.