Skip to content

🔒 Securely hash security PINs - #30

Open
apil-khadka wants to merge 1 commit into
mainfrom
jules-14822167893375426440-affef9b1
Open

🔒 Securely hash security PINs#30
apil-khadka wants to merge 1 commit into
mainfrom
jules-14822167893375426440-affef9b1

Conversation

@apil-khadka

Copy link
Copy Markdown
Owner

🎯 What: The vulnerability fixed
The application previously stored the user's security PIN in plaintext in SharedPreferences. This has been updated to hash the PIN before storage.

⚠️ Risk: The potential impact if left unfixed
A plaintext PIN stored in SharedPreferences can be extracted by an attacker with physical access to a rooted device, an ADB backup (if enabled), or any process running with root privileges, leading to unauthorized access to the application. Given that a PIN is typically short (4-6 digits), an offline attacker could easily extract and brute force it.

🛡️ Solution: How the fix addresses the vulnerability
The vulnerable getPin method was removed and replaced with safe hasPin and verifyPin methods.
The PIN is now securely hashed using PBKDF2WithHmacSHA256 with 10,000 iterations and a securely generated, randomly-salted 16-byte array, preventing offline brute-force and dictionary attacks. The salt is uniquely generated per-PIN and stored alongside the hashed data.
Additionally, backward compatibility logic was carefully added to transparently migrate existing plaintext PINs to the new hashed format upon a user's next successful login, preventing lockouts for legacy users.


PR created automatically by Jules for task 14822167893375426440 started by @apil-khadka

🎯 What:
The application previously stored the user's security PIN in plaintext in SharedPreferences. This has been updated to hash the PIN before storage.

⚠️ Risk:
A plaintext PIN stored in SharedPreferences can be extracted by an attacker with physical access to a rooted device, an ADB backup (if enabled), or any process running with root privileges, leading to unauthorized access to the application.

🛡️ Solution:
The `getPin` method was removed and replaced with `hasPin` and `verifyPin`.
The PIN is now securely hashed using `PBKDF2WithHmacSHA256` with 10,000 iterations and a securely generated, randomly-salted 16-byte array, preventing offline brute-force attacks.
Additionally, backward compatibility logic was added to seamlessly migrate existing plaintext PINs to the new hashed format during the next login.

Co-authored-by: apil-khadka <87198819+apil-khadka@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@coderabbitai

coderabbitai Bot commented Mar 22, 2026

Copy link
Copy Markdown

Warning

Rate limit exceeded

@apil-khadka has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 24 minutes and 37 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 960ebc4b-7ab8-41c9-b12e-3b08ce233af4

📥 Commits

Reviewing files that changed from the base of the PR and between 782a5d1 and 3c2b07c.

📒 Files selected for processing (2)
  • app/src/main/java/dev/nyxigale/aichopaicho/AppPreferenceUtils.kt
  • app/src/main/java/dev/nyxigale/aichopaicho/viewmodel/SecurityViewModel.kt
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jules-14822167893375426440-affef9b1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Tip

You can disable poems in the walkthrough.

Disable the reviews.poem setting to disable the poems in the walkthrough.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant