Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ERTP, Zoe] How does ERTP/Zoe/UIs address social attacks related to displaying amounts? #589

Closed
DavidBruant opened this issue Feb 21, 2020 · 2 comments
Labels
ERTP package: ERTP security Zoe package: Zoe

Comments

@DavidBruant
Copy link
Contributor

I'm creating a separate issue to discuss what started in another issue : #521 (comment)

I'm concerned that there is a social attack here where a user will simply look at the data and see that it matches, but it is actually a different object identity.

I don't understand a specific attack scenario, so it's not clear to me what ERTP/Zoe/UIs is defending against nor whether it's doing a good job at protecting against it

@katelynsills
Copy link
Contributor

Thanks for making this issue!

@katelynsills katelynsills added ERTP package: ERTP Zoe package: Zoe labels Feb 21, 2020
@katelynsills katelynsills changed the title How does ERTP/Zoe/UIs address social attacks related to displaying amounts? [ERTP, Zoe] How does ERTP/Zoe/UIs address social attacks related to displaying amounts? Feb 21, 2020
@katelynsills
Copy link
Contributor

Closing this because we have a wallet that can display non-fungible amounts, so the display issues are no longer theoretical.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ERTP package: ERTP security Zoe package: Zoe
Projects
None yet
Development

No branches or pull requests

3 participants