Security should be more aggressive on Access Token. #1429

Closed
opened 2018-05-02 20:52:17 +02:00 by ICTman1076 · 2 comments
ICTman1076 commented 2018-05-02 20:52:17 +02:00 (Migrated from github.com)

The Issue

Security on the new LBRY app is, in my opinion, too tame, and allows people to get fooled by scammers/attackers easily. In this issue I will outline what happens at the moment, and what I think should happen.

This is one of two issues submitted that are linked. This one is related to the access token. The other is issue #1430.

Steps to Reproduce

  1. On menu bar, click help.
  2. Scroll down to the bottom, and click "view" next to "access token".

How I think it should behave

I feel a huge, obnoxious box should pop up saying something along the lines of "Be careful not to give this to hackers/attackers, it could give them access to all your LBC", ensuring the person isn't being scammed.

Actual Behaviour

No confirmation box, and only a tiny, tiny piece of text as warning that can easily be missed.

System Configuration

N/A, since this change should be for all systems. The only piece of information you may need about this is that I have the latest beta "redesign" build.

Let me know if you want any more information. Thanks!

<!-- Thanks for reporting an issue to LBRY and helping us improve! To make it possible for us to help you, please fill out below information carefully. Before reporting any issues, please make sure that you're using the latest version. - App releases: https://github.com/lbryio/lbry-app/releases - Standalone daemon: https://github.com/lbryio/lbry/releases We are also available on live chat at https://chat.lbry.io --> ## The Issue Security on the new LBRY app is, in my opinion, too tame, and allows people to get fooled by scammers/attackers easily. In this issue I will outline what happens at the moment, and what I think should happen. This is one of two issues submitted that are linked. This one is related to the access token. The other is issue #1430. ### Steps to Reproduce 1. On menu bar, click help. 2. Scroll down to the bottom, and click "view" next to "access token". ### How I think it should behave I feel a huge, obnoxious box should pop up saying something along the lines of "Be careful not to give this to hackers/attackers, it could give them access to all your LBC", ensuring the person isn't being scammed. ### Actual Behaviour No confirmation box, and only a tiny, tiny piece of text as warning that can easily be missed. ## System Configuration N/A, since this change should be for all systems. The only piece of information you may need about this is that I have the latest beta "redesign" build. Let me know if you want any more information. Thanks!
kauffj commented 2018-05-03 01:08:11 +02:00 (Migrated from github.com)

While I don't disagree with the principle/idea, this access token just lets you earn rewards on behalf of a user. It does not grant wallet access.

While I don't disagree with the principle/idea, this access token just lets you earn rewards on behalf of a user. It does not grant wallet access.
alyssaoc commented 2018-10-16 19:22:22 +02:00 (Migrated from github.com)

closing, no plan to change in the short term.

closing, no plan to change in the short term.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
LBRYCommunity/lbry-desktop#1429
No description provided.