Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Privacy Proposal #4269

Closed
sullof opened this issue May 16, 2018 · 1 comment
Closed

Privacy Proposal #4269

sullof opened this issue May 16, 2018 · 1 comment

Comments

@sullof
Copy link

sullof commented May 16, 2018

I am building Tweedentity, an identity system based on Twitter and Ethereum. This would allow people to log in DApps without username and password, but just showing the DApp that they are the owner of that Twitter account.
The big problem using Metamask is that when it is active, it injects web3 and users' info in any tab. This does not allow the users to decide which DApp can see their info and which app can't.
There is also a security issue because when a tab intercepts my wallet, the tab can generate a transaction hoping that I submit it inadvertently.
Is there any plan to add a settable option that requires an explicit approval before injecting web3 in a specific tab?

@bdresser
Copy link
Contributor

bdresser commented Jun 5, 2018

thanks @sullof - we're aware and taking steps towards a full solution tracked in #714

@bdresser bdresser closed this as completed Jun 5, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants