You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Image files should be pre-validated by the wallet/authenticator's team prior to being used. They should go through both mechanical sanitizers as well as human eyes and should be retrieved from key authenticated backends which are fully controlled by the team and not any third parties.
Because of this, adding images to ricardians is a danger to wallets and users which could lead to remote execution and complete loss of funds.
The text was updated successfully, but these errors were encountered:
nsjames
changed the title
Images should be taken out of the spec.
Remove images from the spec.
May 12, 2019
Images are known to be vulnerable
Image files should be pre-validated by the wallet/authenticator's team prior to being used. They should go through both mechanical sanitizers as well as human eyes and should be retrieved from key authenticated backends which are fully controlled by the team and not any third parties.
Because of this, adding images to ricardians is a danger to wallets and users which could lead to remote execution and complete loss of funds.
The text was updated successfully, but these errors were encountered: