bitcoin-dev

BIP Proposal - Address Paste Improvement

BIP Proposal - Address Paste Improvement

Original Postby Dmitry Petukhov

Posted on: November 8, 2018 08:11 UTC

The act of copying addresses to the clipboard should not be supported but discouraged as it is a low-hanging fruit for malware.

If a computer is compromised, malware can easily replace an address with another one. This can also happen when viewing QR codes. Therefore, some form of authentication for an address is needed to protect against this kind of attack. Possible solutions include using 2FA (transfer checksum via second channel), visual fingerprints that are difficult to detect and replace for malware, signing the destination address with the key of an address that is already known, and checking the signature. However, the challenge is to find an address authentication procedure that will be convenient for users and widely supported. Despite the need for authentication, there is still a demand for a convenient mechanism for end users to transfer an address from a web page to the wallet address input field.