Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

randomize seed phrase backup .txt file name #7687

Closed
dpazdan opened this issue Dec 11, 2019 · 0 comments · Fixed by #7863
Closed

randomize seed phrase backup .txt file name #7687

dpazdan opened this issue Dec 11, 2019 · 0 comments · Fixed by #7863

Comments

@dpazdan
Copy link

dpazdan commented Dec 11, 2019

What problem are you trying to solve?
When someone clicks on:

Download this Secret Backup Phrase and keep it stored safely on an external encrypted hard drive or storage medium.

It will download a file that is named: MetaMask Secret Backup Phrase.txt. This can be used by anyone that knows this to search computers for the file that holds clear text seed phrases.

Describe the solution you'd like
For security purposes, we should randomize the name of the file. Or at a minimum we should state clearly in the instructions, that the user should rename the file.

Change to:
Download this Secret Backup Phrase

  1. rename the file.
  2. keep it stored safely on an external encrypted hard drive or storage medium.

reference: https://www.reddit.com/r/Metamask/comments/e90pae/key_file_download/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants