Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature]: Require PIN for payments for transfers made with Manual Setup flow #2298

Open
catch-21 opened this issue Oct 9, 2024 · 0 comments
Labels
enhancement New feature or request feature request A user has an idea for the app

Comments

@catch-21
Copy link
Contributor

catch-21 commented Oct 9, 2024

Describe the problem

With 'Require PIN for payments' enabled, only regular payments are protected. Now we have the option to send onchain to any LN node (not just Blocktank), it is possible for a malicious actor to use their own LN node to extract funds from the bitkit wallet because this action it not PIN protected.

Describe the solution

It would be good to protect the payment step of the Manual Setup flow with the PIN/Biometric when this setting is enabled. Alternatively, we could add an separate toggle but that is adding to complexity.

Additional context

No response

@catch-21 catch-21 added enhancement New feature or request feature request A user has an idea for the app labels Oct 9, 2024
@catch-21 catch-21 changed the title [Feature]: Require PIN for payments cover transfers with Manual Setup [Feature]: Require PIN for payments for transfers made with Manual Setup flow Oct 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request feature request A user has an idea for the app
Projects
None yet
Development

No branches or pull requests

1 participant