Bitcoin-com / Wallet

MIT License
332 stars 233 forks source link

Viewing seed phrase does not require authentication #596

Closed davidhudman closed 2 years ago

davidhudman commented 2 years ago

Present in Android app.

Pretty simple to reproduce. What is strange is that authentication is required to send funds.

I will look into how this can be resolved unless someone has a quick fix. It seems that malware could exploit this and copy / screenshot a user's seed phrase.

RolandTMJ commented 2 years ago

Why would anyone see end there seed phrase. Say i have two backup keys encrypted I'm trying to get my btc from btc.com but don't know how an anyone help.

On Tue, Jan 25, 2022, 6:20 PM David Hudman @.***> wrote:

Present in Android app.

I will look into how this can be resolved unless someone has a quick fix. It seems that malware could exploit this and copy / screenshot a user's seed phrase.

— Reply to this email directly, view it on GitHub https://github.com/Bitcoin-com/Wallet/issues/596, or unsubscribe https://github.com/notifications/unsubscribe-auth/AU6LUMQHHNJWRA4ATECL3CTUX5K5DANCNFSM5MZ3SJUQ . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

You are receiving this because you are subscribed to this thread.Message ID: @.***>

davidhudman commented 2 years ago

I must have added this to the wrong repo since there have been no commits since 2019 but the issue has been resolved. I don't think I had my settings wrong, but it's possible.