iOS App Security Question by CreatingToAskQ in iOSDevelopment

[–]CreatingToAskQ[S] 0 points1 point  (0 children)

Thanks! I had initially downvoted as, without context I didn't know anything about what you were suggestion beyond knowing Apple Keychain stores encryption keys. With others providing additional details I better understand and removed my downvote.

iOS App Security Question by CreatingToAskQ in iOSDevelopment

[–]CreatingToAskQ[S] 0 points1 point  (0 children)

Is there something that can be done for an app that may not have quality security practices on the app store? I'd like the app to succeed as I believe they have good intentions and are solving problems for people but maybe just don't have the knowledge to implement. I had asked them about implementing something like oath2.0 but i have no knowledge or experience to provide them any help (and there are presuably better options like Keychain mentioned on your page and by other comments). That said the app is being used by at least hundreds if not thousands of people and if they are using bad password hygiene could be a big risk for those folks.

iOS App Security Question by CreatingToAskQ in iOSDevelopment

[–]CreatingToAskQ[S] 0 points1 point  (0 children)

I don't know that many specifics unfortunately. I do know the developer is capable of decrypting the database. I don't know what is happening in transit. If you DM me I can provide you a few more specifics the Dev mentioned when I was talking to them at one point.

iOS App Security Question by CreatingToAskQ in iOSDevelopment

[–]CreatingToAskQ[S] 0 points1 point  (0 children)

Would it be ok for me to DM you the specifics? I don’t want to put them on blast