MetaMask / MetaMask/metamask-mobile

Security improvement: MetaMask iOS doesn't comply with passcode security level as Trust Wallet or Unstoppable Wallet does

Open
#5,017 0 comments 0 reactions 0 assignees View on GitHub
type-enhancement type-security
Dominant language
TypeScript
Stars
3k
Forks
1.7k
Avg merge
1d 14h
Merged PRs (30d)
669

Description

**Describe the bug**
On Trust Wallet mobile, after 5 wrong 6-digits-PIN entries, wallet is erased
On Unstoppable Wallet mobile, after 5 wrong 6-digits PIN entries, you have an increased delay to make the next try
On MetaMask mobile, even if the password includes ASCII chars and not only digits, the problem is you can proceed with unlimited tries ➜ brute-force possible.

**Smartphone (please complete the following information):**
- especially iOS and last Android too
- App Version [5.6.1 (967)]

![IMG_8083](https://user-images.githubusercontent.com/64386272/191689564-06dd41a0-3855-4f77-a21d-30d4cad0a993.PNG)
![IMG_8084](https://user-images.githubusercontent.com/64386272/191689570-813776e8-2eeb-4643-b6d5-c0eccf94218e.PNG)

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by reproducing the unlimited-tries behavior on iOS and Android at app version 5.6.1 (967), then define and verify the agreed lockout or delay behavior for repeated failed passcode attempts.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, ios, react-native, typescript
Domain
authentication, mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.