metamask-mobile icon indicating copy to clipboard operation
metamask-mobile copied to clipboard

[Bug]: PPOM - Hide "checking for security alerts" message and banners for errors on `personal_sign` requests

Open seaona opened this issue 1 year ago • 1 comments

What is this about?

Slack thread.

We don't have evidence that any personal sign request can be malicious at the moment so, although we'll persist security alert validation in the background, we should smoothen the UX by hiding:

  1. "Checking for security alerts" banner
  2. "No security alerts found" banner
  3. Error banner in case validation fails

Screenshots/Recordings

Steps to reproduce

  1. Enable Blockaid from settings
  2. Go to the test dapp
  3. Trigger a personal signature
  4. See Blockaid is running a validation and a Blockaid banner appears

Error messages or log output

No response

Version

7.16.0

Build type

None

Device

Pixel 6

Operating system

iOS, Android

Additional context

No response

Severity

No response

seaona avatar Jan 30 '24 16:01 seaona

Currently blockaid will always report personal_sign and benign as no one is exploiting personal sign currently. But it is still worth keeping the validation as a malicious use of personal_sign in future is definitely is possibility.

Please check more discussion here: https://consensys.slack.com/archives/C070G0RCX0T/p1719402457487879

Thus we should remote blockaid loader and validation failed messages from personal_sign but still keep validating them.

jpuri avatar Jun 26 '24 12:06 jpuri

Closing as no longer relevant as we have reduced the latency and error rate of security alerts

bschorchit avatar Jan 28 '25 15:01 bschorchit