MetaMask / MetaMask/metamask-mobile

Metamask website partially insecure

Open
#2,985 0 comments 0 reactions 0 assignees View on GitHub
community
Dominant language
TypeScript
Stars
3k
Forks
1.7k
Avg merge
1d 14h
Merged PRs (30d)
669

Description

Hi,

I am currently looking at some wallets to choose from and as security is a very important point (if not the most important), I checked some wallet providers' websites regarding security precautions. I have my own ways and means to do so, but in order to make the problem visible and tracable for anyone interested, I just used Webkoll.

The result for Metamask was a quite sobering, as it shows that content security is not implemented and that the website's referrers leak. I attach a screenshot, which shows what should be improved. Anyone interested can view the result by typing "https://metamask.io/" in the form on the webkoll website: https://webbkoll.dataskydd.net/
The result you'll find attached will be stored on their website for 24 hours from now on, but you can also check the results later by doing the same as described above.

In general I find it very hard to trust a wallet if the wallet provider's website is partially unsecure.
Apart from the depicted security risks as shown on the Webkoll screenshot, I think that any safety-concious person interested in crypto won't be amused when becoming aware of the fact that 95 % of the third party requests on the Metamask website come from Google in order to fingerprint browsers etc. As I think that most people don't like the fact that Google is collecting our private data and spys on everyone as often as possible, serious wallet providers should configure their websites in a way that there are no links to Google none whatsoever (and please don't say now that we need them for 2FA! There are other much more secure options than Google. Just use a stick like the NitroKey, Yubikey etc. ...).

So I hope that Metamask's security people will read this and **react by improving** what has to be improved. If so, I'd be happy to hear in the near future that those problems have been solved. Thank you.

![MetaMask_website_security_risks](https://user-images.githubusercontent.com/88577757/128597425-d6b3de3d-030e-4ef8-ad50-13edc4aea6fd.jpg)

Contributor guide

Open the contributing guide

Research direction

No repository file, test, or entry point is identified. Start by reproducing the reported metamask.io results with Webkoll and reviewing the attached screenshot, then determine which repository owns the website configuration. Done requires an agreed scope for the reported security findings and verification that those findings are resolved.

Written by the indexing model from the issue text.

Assessment

Domain
security, web-dev
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.