MetaMask / metamask-mobile

Mobile web browser providing access to websites that use the Ethereum blockchain
https://metamask.io
Other
2.05k stars 1.07k forks source link

Block phishing sites #275

Closed brunobar79 closed 5 years ago

brunobar79 commented 5 years ago

We should use the PhisingController and block blacklisted websites like we do on the extension.

@bdresser @cjeria We will need to adapt the phising screen of the extension to mobile

omnat commented 5 years ago

Insights from this paper on how we could design so that user understands what the warning is and increase chances that they adhere to security warning instead of taking a risk https://ai.google/research/pubs/pub46632

TLDR:

Opportunity to educate about the specific property of the security that seems vulnerable. Make it clear that when a warning appears on a trusted site, there’s more reason for users should NOT proceed.

Opportunity to make MM security warnings looks and feel trusted and actionable (on what could user do to continue)