deeper-chain / DeveloperCommunity

Build with the best Deeperchain ecosystems
2 stars 6 forks source link

AtomOS login username and security concerns under DPR tab #15

Open A1Frontier opened 2 years ago

A1Frontier commented 2 years ago

Description To login all Deeper Devices with the same user name “admin” No protection /no security/ no 2FA to get access for DPR’s wallet address which can transfer DPRs to any wallet address in Deeper Main Net

Steps to reproduce .

  1. Reboot the mini
  2. Reboot the router
  3. Clear the caches from the browser
  4. Login 11.22.33.44 and/or 34.34.34.34 by using the same user name for different deeper network devices.
  5. To be able to change the password, but not able to change the user name.
  6. Once login, the user can do anything everything for DPR tab, including changing the wallet address, binding/unbinding the wallet address, transferring DPRS, etc
  7. Need additional protection for the DPR tab.

Expected result The DPR tab needs additional security protection. 2FA (email, text, google authenticator need to be in place in order to protect DPR transactions.

Actual result Not meeting basic security requirements for the DPR token.

Notes Can dev team estimate the deadline when 2FA for DPR tab is available?

zhuo2 commented 2 years ago

Very good suggestion

Charles08 commented 2 years ago

Never thought about this until I read it. Nice suggestion!!!