You are viewing a single comment's thread from:

RE: HiveSigner is INSECURE? - discussion and deep dive

in HiveDevs8 days ago

You can pre-add the authority through other interfaces like PeakD and Hive.blog.
I believe everything should support keychain, but even that isn't audited.

Sort:  

Yes, which is probably the most secure way to use HiveSigner!

What would an "audit" or auditor do?

Keep an eye on the github repo?
Look for exploits in the live app?
"PenTest" the company itself?

Generally review the code for security issues and/or exploits. Ideally, regularly, but most are lucky if it is even done once halfassed.

Loading...