Security should be more aggressive on DevTools. #1430

Closed
opened 2018-05-02 20:58:21 +02:00 by ICTman1076 · 3 comments
ICTman1076 commented 2018-05-02 20:58:21 +02:00 (Migrated from github.com)

The Issue

Security on the new LBRY app is, in my opinion, too tame, and allows people to get fooled by scammers/attackers easily. In this issue I will outline what happens at the moment, and what I think should happen.

This is one of two issues submitted that are linked. This one is related to the DevTools. The other is issue #1429.

Steps to Reproduce

  1. In the app, press Ctrl-Shift-I
  2. Click on console tab.

How I think it should behave

In the console, it should be made clear that pasting unknown code into it is potentially dangerous. Discord handles this well - https://ictman.tk/img/020518_01-46-53.png. If you want to implement something like this, then this StackOverflow question may help

Actual Behaviour

Nothing.

System Configuration

N/A, since this change should be for all systems. The only piece of information you may need about this is that I have the latest beta "redesign" build.

Let me know if you want any more information. Thanks!

<!-- Thanks for reporting an issue to LBRY and helping us improve! To make it possible for us to help you, please fill out below information carefully. Before reporting any issues, please make sure that you're using the latest version. - App releases: https://github.com/lbryio/lbry-app/releases - Standalone daemon: https://github.com/lbryio/lbry/releases We are also available on live chat at https://chat.lbry.io --> ## The Issue Security on the new LBRY app is, in my opinion, too tame, and allows people to get fooled by scammers/attackers easily. In this issue I will outline what happens at the moment, and what I think should happen. This is one of two issues submitted that are linked. This one is related to the DevTools. The other is issue #1429. ### Steps to Reproduce 1. In the app, press Ctrl-Shift-I 2. Click on console tab. ### How I think it should behave In the console, it should be made clear that pasting unknown code into it is potentially dangerous. Discord handles this well - https://ictman.tk/img/020518_01-46-53.png. If you want to implement something like this, then [this StackOverflow question](https://stackoverflow.com/questions/22155879/how-do-i-create-formatted-javascript-console-log-messages) may help ### Actual Behaviour Nothing. ## System Configuration N/A, since this change should be for all systems. The only piece of information you may need about this is that I have the latest beta "redesign" build. Let me know if you want any more information. Thanks!
kauffj commented 2018-05-03 01:09:28 +02:00 (Migrated from github.com)

Thanks @ICTman1076 this is a great idea! If you have any interest in completing this yourself, we'd be happy to bounty.

Thanks @ICTman1076 this is a great idea! If you have any interest in completing this yourself, we'd be happy to bounty.
tiger5226 commented 2018-05-19 02:14:58 +02:00 (Migrated from github.com)

Thats an awesome warning message +1 Discord

Thats an awesome warning message +1 Discord
tzarebczan commented 2018-06-21 07:56:57 +02:00 (Migrated from github.com)
This is fixed in : https://github.com/lbryio/lbry-app/pull/1500
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
LBRYCommunity/lbry-desktop#1430
No description provided.