Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Brave Browser Blocking Legitimate Site moonbeam.network #16086

Closed
distractivekatie opened this issue May 26, 2021 · 8 comments
Closed

Brave Browser Blocking Legitimate Site moonbeam.network #16086

distractivekatie opened this issue May 26, 2021 · 8 comments
Assignees
Labels

Comments

@distractivekatie
Copy link

Description

Brave browser is issuing a phishing detection warning for a Polkadot parachain site, https://moonbeam.network/. The site is legitimate and contains no solicitations of user information, nor does it make requests to any wallet provider. It's a static website.
Note: there is a subdomain for the documentation site that is hosted in mkdocs (https://docs.moonbeam.network/) that contains a "connect to MetaMask" button, but this is not malicious and simply allows users to connect their MetaMask to our TestNet: https://docs.moonbeam.network/getting-started/testnet/metamask/

Steps to Reproduce

  1. Navigate to https://moonbeam.network/
  2. Receive warning from Brave

We received reports of this behavior as early as last week but were not able to reproduce until now. It seems to be related to the IP address of the user, since I am now traveling and accessed the website from a different location. Only experienced it on the browser so far.

Actual result:

image

Expected result:

image

Reproduces how often:

Intermittent issue: does not happen for every user every time.

Brave version (brave://version info)

Brave 1.24.86 Chromium: 90.0.4430.212 (Official Build) (64-bit)
Revision e3cd97fc771b893b7fd1879196d1215b622c2bed-refs/branch-heads/4430@{#1429}
OS Windows 10 OS Version 2009 (Build 19042.985)

Version/Channel Information:

N/A

  • Can you reproduce this issue with the current release? Yes
  • Can you reproduce this issue with the beta channel? I don't know what this is
  • Can you reproduce this issue with the nightly channel? I don't know what this is

Other Additional Information:

  • Does the issue resolve itself when disabling Brave Shields? Now that I have clicked "proceed anyway," it will not give me the screen again
  • Does the issue resolve itself when disabling Brave Rewards? Now that I have clicked "proceed anyway," it will not give me the screen again
  • Is the issue reproducible on the latest version of Chrome? No, only Brave

Miscellaneous Information:

Your link on the warning asks people to "file an issue" but does not have a hyperlink or say where. There should be a better place for projects to prove their authenticity so they are not erroneously blocked.

@A9qx
Copy link

A9qx commented May 26, 2021

I'm on Brave as we speak, I tried out the website and didn't find an issue. Loaded as Normal.

@distractivekatie
Copy link
Author

I am not sure what triggers the behavior but I received it a second time when accessing a different subdomain. I'll note that I am traveling and accessing the website from a different IP than usual... I have accessed it many times previously without issue. I am not clear what is triggering the error but we did also submit requests to all the crypto DBs to whitelist the domain.
image (7)

@No5251
Copy link

No5251 commented May 28, 2021

Maybe the same problem as with reddit before?
https://community.brave.com/t/reddit-is-blocked-by-crypto-wallet/242391

@distractivekatie
Copy link
Author

Yes, same problem, but we are not listed in the CryptoScamsDB. I have also contacted them to see if they can do something anyway. Is that the only DB the Brave Wallet uses to make these kinds of blocks on domains? It makes it really difficult for those who are legit projects to get it removed bc their team is not responsive.

@bbondy
Copy link
Member

bbondy commented May 28, 2021

cc @jonathansampson if you can help with this

@jonathansampson
Copy link
Contributor

@bbondy Looking into this now.

jonathansampson added a commit to phishfort/phishfort-lists that referenced this issue May 28, 2021
@jonathansampson
Copy link
Contributor

@purestakatie Thank you for reporting. I've removed the domain from the blacklist; it should be updated for our users shortly. Our apologies for the inconvenience, and please do reach out if you ever encounter any other issues.

@distractivekatie
Copy link
Author

AMAZING thank you guys for being so quick about this!

@bbondy bbondy added the feature/web3/wallet Integrating Ethereum+ wallet support label Nov 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants