WalletCrx
WalletCrx copied to clipboard
Chrome extension wallet does not automatically hide consumed receive address once funds are received.
When the Chrome extension receives funds and this is indicated by a message that fades in/out and a sound, the wallet fails to perform the following privacy-preserving functions:
- The QR code of the address that just received funds is not hidden automatically.
- Once the QR code display is manually exited by the user, a new receiving address will not be displayed to the user. The user must manually click away from the Receive Money tab and return to it in order to see a new receiving address.
By not meeting these specifications, users are more likely to unwittingly reuse receive addresses without understanding the privacy consequences. Also, additional clicks to reveal a new receive address mean that users are less likely to put in the effort, as demonstrated by various UI studies of # clicks vs. user participation to perform a given action.
Hmmm... 2 years old and no response. Is this still an issue?
Ps: maybe obsolete considering #23