MetaMask / MetaMask/metamask-extension
Enable mobile authentication using multi-sig technology
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
**What problem are you trying to solve?**
Many users are worried that they will lose their funds in their MetaMask wallet because of hacks and phishing attacks. As a result, they either avoid using MetaMask or transfer their large portion of their funds out of their MetaMask wallet after a transaction has been completed.
**Describe the solution you'd like**
Leverage multi sig technology to create mobile authentication for the transactions. The idea is to create separate wallet on the user's mobile device using a stand alone MetaMask app and then use the app as the signatory for transactions.
Design the UI of the MetaMask mobile app in a way that makes the app only useful for signing transactions. This enables an authentication of the transaction using a separate device. So, even if user's computer is stolen, the attacker can not transfer the funds out of the account.
NOTE: to avoid a situation where an attacker creates the mobile authentication, only allow creation of mobile authentication at the time of MetaMask wallet plugin set up.
Please review attached presentation on the details of the proposal and the wireframe.
**Additional context**
You can click on the call to actions for happy path to see user flow below.
The wireframe on desktop (plugin) : https://preview.uxpin.com/e547e1067378fbdde86fe3498f75f2df2873ce4e#/pages/92234951/simulate/no-panels?mode=i
The wireframe on Mobile app (MVP): https://preview.uxpin.com/e547e1067378fbdde86fe3498f75f2df2873ce4e#/pages/92237493/simulate/no-panels?mode=i
Presentation is attached.
[Product Improvement for MetaMask .pdf](https://github.com/MetaMask/metamask-extension/files/2350754/Product.Improvement.for.MetaMask.pdf)
Contributor guide
Research direction
Start by reviewing the attached Product Improvement for MetaMask PDF and the linked desktop and mobile UXPin wireframes. The proposal needs an agreed implementation scope and entry points before work can begin; done would require the mobile signing flow and setup restriction to be specified sufficiently for implementation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- authentication, blockchain, mobile-dev, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100