-
Notifications
You must be signed in to change notification settings - Fork 15
Closed
Description
During the OAuth Security Workshop, Fabian's formal analysis highlighted that it is very hard to ensure the pre-auth code gets into the intended wallet. even when the PIN is used, if the QRcode with pre-auth code is scanned by a malicious wallet, chances are high that the user will type in the correct PIN received via a separate channel in the malicious wallet.
At the same time, I am reluctant to remove this flow, because it is important for the issuance when user authentication is done in-person in the government office.