signum-network / signum-xt-wallet

Cryptocurrency wallet for the green Signum 🍀 blockchain as an extension for your browser.
MIT License
14 stars 6 forks source link

PIN code for transaction execution #11

Open alicks opened 2 years ago

alicks commented 2 years ago

Probavly new Feature.

Is your feature request related to a problem? Please describe. It would be good if Wallet will execute transactions only after another user interaction - i.e. entering predefined PIN (same way as BTDEX). As there are a lot of Scam projects, those can do TXs without any user's attendace, if it authorized by Wallet. Of course that have to be permitted first by user during authorization Web portal/project in Wallet, but sometimes user might not pay needed attention. Hence, assets can be potentially stolen by scammers..

Describe the solution you'd like User should always enter a PIN code for any TX in Wallet, besides password. Hence, user will be fully aware that no TXs will take place without his attention. even if Scam portal/project have been authoraized in Wallet before.

Describe alternatives you've considered

  1. Warnings that any portal that user will authorized - is a potentional Scamer. Perhaps, as a Disclaimer to user.
  2. Not allow any "automatic" TXs even if Portal have been authorized by user before.
  3. Wallet can ask Scam Database if this particular project have been reported as Scammer.

BR, alicksad (my discord name).

frankTheTank72 commented 2 years ago

A transaction is always shown first and says what will be paid - you need to click again for signing - this is a standard process for all extension from the top blockchains - don´t see why we should complicate the stuff ...

alicks commented 2 years ago

I did not get you, Frank.. What i want to say: Somehow there are a lot of victims - people authorizing scam projects/portal in their Wallets (browser extension), but some time after - they see that all coins are lost from there.. How does it happens - idk all details, but definitely user have authorized Scamer first. At least - triggering Scammer's Database (like opensource: https://cryptoscamdb.org/scams) to warn user (that he is authorizing a potentioal scam portal/project) about scammer is needed.

ohager commented 2 years ago

@alicks this is definitely a legit FR. Atm, we do not have sufficient projects such that a scammers database is necessary. As a completion, we might use the chain itself with its built-in messaging feature to keep track of scammy projects. We keep this FR open, but it is very low priority at this time of writing.