Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Privacy issue - user accounts are disclosed when subscribing to accounts change #422

Open
ilanolkies opened this issue Nov 12, 2020 · 0 comments

Comments

@ilanolkies
Copy link

ilanolkies commented Nov 12, 2020

What browser and version did you use?

Google Chrome latest

What operating system did you use?

Mac OS

Do you have screenshots showing the problem?

Screen Shot 2020-11-12 at 19 34 31

What is your issue?

If developer suscribes to accounts change and the user accepts to share one wallet, the developer can then listen to all user's accounts when one changes. I created an account to use in one dapp and another in another dapp. When I went back to the first dapp I selected back my account and it logged all the accounts i have ever created... This is leaking user information.

I think it would be good to analyse new Metamask features that lets user select the selected account and the share only that account in the array of accounts logged by account changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant