brave-browser icon indicating copy to clipboard operation
brave-browser copied to clipboard

Add additional Password-protection for Wallet Backup Seed reveal

Open josheleonard opened this issue 2 years ago • 0 comments

Description

To increase the overall security, revealing the Brave Wallet backup seed phrase from should require re-entering the wallet password

Steps to Reproduce

  1. Unlock the Brave wallet
  2. Navigate to Portfolio Screen -> Click the "..." icon -> Select "Back up Now" -> Agree to Terms -> Continue

Actual result:

Seed is revealed without additional credential check

Expected result:

User is prompted to enter their password before they can click the "continue" button

josheleonard avatar Aug 08 '22 23:08 josheleonard

@josheleonard is this from the doyensec audit?

diracdeltas avatar Aug 10 '22 20:08 diracdeltas