MetaMask / MetaMask/metamask-mobile
2023 Q1: Privacy Improvements
- Dominant language
- TypeScript
- Stars
- 3k
- Forks
- 1.7k
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 669
Description
Review/Update Privacy Settings
1. Make it easy and more discoverable to review/update all privacy settings (including RPC provider, other 3rd party APIs we call) - for new and existing users
2. For new users, don't send any network requests till they've opted to continue with default privacy settings or have updated their settings from the prompt shown after wallet creation/import steps
Audit and clean-up metrics for any potentially sensitive info
1. User opt-ins: clearer metrics opt-in language, & explicit opt-in to privacy policy
2. Internal data audits, hunting for any _possibly_ user identifiable or sensitive info that's getting stored accidently
3. Events & properties sanitzation
Optionality of RPC provider
1. In the flow when a site suggests to add a network. Add RPC provider edition option here, while continuing to mitigate phishing risks
Contributor guide
Research direction
No files, tests, or entry points are named. Start by mapping the wallet creation/import privacy prompt, privacy settings, RPC-provider configuration, network-request initialization, and metrics/event collection described in the issue. Done requires agreed behavior for first-run requests, discoverable settings, opt-in wording, data sanitization, audits, and RPC-provider editing, but the broad scope needs maintainer direction first.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- react-native, typescript
- Domain
- analytics, api, mobile, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100