You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With 'Require PIN for payments' enabled, only regular payments are protected. Now we have the option to send onchain to any LN node (not just Blocktank), it is possible for a malicious actor to use their own LN node to extract funds from the bitkit wallet because this action it not PIN protected.
Describe the solution
It would be good to protect the payment step of the Manual Setup flow with the PIN/Biometric when this setting is enabled. Alternatively, we could add an separate toggle but that is adding to complexity.
Additional context
No response
The text was updated successfully, but these errors were encountered:
catch-21
changed the title
[Feature]: Require PIN for payments cover transfers with Manual Setup
[Feature]: Require PIN for payments for transfers made with Manual Setup flow
Oct 9, 2024
Describe the problem
With 'Require PIN for payments' enabled, only regular payments are protected. Now we have the option to send onchain to any LN node (not just Blocktank), it is possible for a malicious actor to use their own LN node to extract funds from the bitkit wallet because this action it not PIN protected.
Describe the solution
It would be good to protect the payment step of the Manual Setup flow with the PIN/Biometric when this setting is enabled. Alternatively, we could add an separate toggle but that is adding to complexity.
Additional context
No response
The text was updated successfully, but these errors were encountered: