horizontalsystems / unstoppable-wallet-android

A powerful non-custodial multi-wallet for Bitcoin, Ethereum, Binance Smart Chain, Avalanche, Solana and other blockchains. Non-custodial crypto and NFT storage, onchain decentralized exchange, institutional grade analytics for cryptcurrency and NFT markets, extensive privacy controls and human oriented design. Implemented on Kotlin.
https://unstoppable.money
MIT License
825 stars 356 forks source link

Security ideas / features #1064

Open esengulov opened 4 years ago

esengulov commented 4 years ago
Giszmo commented 3 years ago

This should be split into independent issues as these are independent ideas. If an idea is not worth its own issue, it's probably not worth implementing neither.

horsys commented 3 years ago

This should be split into independent issues as these are independent ideas. If an idea is not worth its own issue, it's probably not worth implementing neither.

Thanks, it's indeed a basket of issues) At one point the issue count became really large so we cleaned it up back then by moving all security issues into one ticket for tracking. We will clean it up in the near future, thanks for heads up ;)

Giszmo commented 3 years ago

Ok, if that is the idea, use a checklist:

...

esengulov commented 3 years ago

Ok, if that is the idea, use a checklist:

  • [ ] View only mode - to monitor portfolio. Only MPK would be required for the app to work in this mode. View only mode.
  • [ ] Disable transactions over 1000 or some other desired amount. This option may include “Require reinstall to remove restrictions”.
  • [ ] Passcode request for anything over certain amount.
  • [ ] blur mode that would hide all sensitive data with blurred overlay. Can be removed on demand from settings. Blures balance on home tab. Everything else stays same. Deactivation of blur takes 5 hours.
  • [ ] Require pin on send.
  • [ ] Require Face ID on send.

...

thanks! cleaned it up a bit )

trymeouteh commented 2 years ago

Would like a optional lock on the app and wallets for additional security

esengulov commented 2 years ago

Would like a optional lock on the app and wallets for additional security

thanks, added it to the above list of improvements

serrq commented 1 year ago

"Double auth for send" feature: I don't want face id or fingerprint id.

In my case I think is better pin A or pin B.

Normal pin (A) is for low value transactions. After a certain amount it needs for "send" a pin too.