Posted by Dmitry Petukhov
Nov 8, 2018/08:11 UTC
The act of copying addresses to the clipboard should not be supported but discouraged as it is a low-hanging fruit for malware. If a computer is compromised, malware can easily replace an address with another one. This can also happen when viewing QR codes. Therefore, some form of authentication for an address is needed to protect against this kind of attack. Possible solutions include using 2FA (transfer checksum via second channel), visual fingerprints that are difficult to detect and replace for malware, signing the destination address with the key of an address that is already known, and checking the signature. However, the challenge is to find an address authentication procedure that will be convenient for users and widely supported. Despite the need for authentication, there is still a demand for a convenient mechanism for end users to transfer an address from a web page to the wallet address input field.
TLDR
We’ll email you summaries of the latest discussions from authoritative bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project?
Give Feedback