Proton Authenticator iOS Bug: Plaintext TOTP Secrets Exposed – Fixed in a Flash! 🚀
Proton’s new iOS Authenticator app had a bug logging TOTP secrets in plaintext. Meaning, your 2FA codes might have been chilling out in debug logs, just waiting for an accidental overshare. Fear not, a fix is out now! And remember, if someone has access to your device, they already hold the keys to your kingdom.

Hot Take:
Proton’s new iOS Authenticator app was like an overenthusiastic waiter who accidentally served your secret recipe to the entire restaurant. Luckily, they’ve cleared the table before anyone got a taste!
Key Points:
- Proton’s iOS Authenticator app had a bug that logged TOTP secrets in plaintext.
- The issue was discovered by a user who noticed missing 2FA entries.
- The bug was related to logging code in the iOS version of the app.
- Proton released a fix (version 1.1.1) to address the logging behavior.
- The bug didn’t pose a remote threat but could expose secrets if logs were shared.
Already a member? Log in here