Replies: 1 comment 2 replies
-
I started a longer discussion at #7830 but the gist of it is that protecting the GUI is only a fraction of what you need to secure your assets. Currently, it's possible to get your seed simply by opening a command line prompt in the client's folder, and running More alarmingly than local access, a virus or trojan could use the RPC interface to make any sends it wants, without you even seeing it if you're not looking directly at the wallet, as well as simply pick your seed unencrypted from the drive. Put simply, a pin for just the send operation is still far too little security. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Good afternoon, I would like to propose an idea, since the chia full node is constantly running, and, accordingly, remains unattended, within the framework of security I would like to propose to implement the functionality, before sending coins to another wallet - a pin code is needed, after three unsuccessful attempts, the entire balance is sent to the backup address.
Beta Was this translation helpful? Give feedback.
All reactions