MyCryptoHQ / MyCrypto

MyCrypto is an open-source tool that allows you to manage your Ethereum accounts privately and securely. Developed by and for the community since 2015, we’re focused on building awesome products that put the power in people’s hands.
https://mycrypto.com
MIT License
1.36k stars 650 forks source link

The Unorganized Roadmap List #194

Closed tayvano closed 6 years ago

tayvano commented 7 years ago

This is not in any order in particular

screen shot 2017-08-23 at 12 21 37 am

Security

New Pages / Functionality

Usability / Content / Non-Dev-vy

skubakdj commented 7 years ago

Phase 1: Add warning to discourage use: "We strongly discourage the use of private keys, keystore files, and mnemonic phrases. Please use an external signer, like MetaMask or a hardware wallet. It's safer & easier. Switch today ->"

Does this apply to all keystore files or just unencrypted keystore files from earlier versions of MEW? If so, what's the rationale?

Edit -- Probably to make phishing more difficult :wink:

tayvano commented 7 years ago

It's to make phishing more difficult and to teach people that entering their private key on a website is not something they should do. There have been a steadily increasing number of comments—not anything to be concerned about yet—pointing out that MEW has normalized people entering their private keys on websites.

We will never 100% not support keys, just make it a bitch to access via keys if you access them on a regular basis. This will enable folks who want to send from cold storage to do so without encouraging active use of keys. This will hopefully reduce the affect of phishers, but also encourage best-practices in the crypto space generally. It is not expected to make a tangible difference in phishing compromises in the short-term.

wbobeirne commented 6 years ago

I'm closing this issue out in favor of more granular, actionable issues. It's also gone a little stale, a lot of these are done. I think it might be good to have a living document off of GitHub that houses a roadmap like this.