You are viewing a single comment's thread from:

RE: Open source Hivesigner Sign In package for Flutter

in #proposal3 years ago

I'm sorry if I got misunderstood, but I personally found successful phishing attempts that happened on #Hivesigner because Hivesigner exists as a website. 😨 I even visited and tested those fake websites (while keeping my real IP address hidden). 🕵️‍♂️ My point is that it is easy to copy the Hivesigner interface and trick users into giving up their private keys and master password. 😰

Regarding the "less maintenance" part, Hivesigner can be used on any web browser without significant additional configurations on the part of both the developers and the users, whereas Hive Keychain needs to be configured by the devs to work on each web browser (Chrome/Brave, Firefox, Safari, and smartphone web browsers). 😳

I'm sorry for saying that Hivesigner is "less safe" than Hive Keychain. 😞 I should have been more positive and said that Hive Keychain is (slightly) more safe. 😰

@chrisrice

Sort:  

Thanks for clarifying where you coming from... Right, phishing attempts are happening in almost every website/project on crypto, because project is opensource. We will add some warning in new website that will at least attempt to create habit to check URL before signing any transaction. Extensions rely on central entity to approve listing, so there is less change to do phishing/copy-paste. Hivesigner had extension, but we removed it because UX wasn't so great. After new UI is out, we might consider bring it back or see if that brings any value.
Also mobile apps, that's why we didn't see any clone of Ecency mobile app, even though it was opensource from the start (also rely on central entities Google, Apple stores).

hivesigner should open a paypal payment like pop up. Could be for some dapps useful,

It is already possible with hivesigner link, you can pay directly anyone from any website. And that link could be opened in popup/iframe that is more user-friendlier.

that's cool. Some idea about phishing? In the last weeks, I see a lot of people that gave aways their keys. Mostly these wallets were used for spam.