No warning if wallet is not protected with password upon creation
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start by tracing the wallet creation password-setting screen in the Windows standalone client, focusing on empty-password handling and the distinction between watch-only and regular wallets. Done means regular wallets cannot be created unprotected without an explicit risk acknowledgement, while watch-only behavior remains appropriate.
Written by the indexing model from the issue text.
Description
2.7.18, Windows standalone version
I was playing around with wallet creation and was surprised that leaving the password boxes empty, I could pass the password-setting screen without any warnings.
Storing seeds and xprv's unencrypted is not a good idea and could do much harm to the unwary novice user. How about making this opt-out? Like, when it's not a watch-only wallet, letting the user though only after ticking a box in a pop-up message that "I've understood the risks" and pressing "OK, proceed unprotected".
- Dominant language
- Python
- Stars
- 8.6k
- Forks
- 3.5k
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 61
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from spesmilo/electrum
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
build/packaging 📦 OS-linux 🐧
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
OS-android🤖
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
All issues in spesmilo/electrum
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
bancolombia/sentinel#23 ·
-
test md OpenCI
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
integration:quickjs org:external priority:backlog topic:code-interpreter topic:middleware type:feature
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
langchain-ai/deepagents#6450 ·
-
bug client
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100