[bisq-network/bisq] When wallet password is enabled private keys are still accessible and BSQ / BTC funds can be send without the need to enter password (#5276)

pazza notifications at github.com
Sat Mar 6 02:14:24 CET 2021


<!--
   SUPPORT REQUESTS: This is for reporting bugs in the Bisq app.
   If you have a support request, please join #support on Bisq's
   Keybase team at https://keybase.io/team/Bisq
-->

### Description

In Bisq when you enable a wallet password you can still access your private keys and send funds without needing your password.

This is not good for security.

Users might comfort knowing if they leave Bisq running while away from computer a password will still be required to send funds.

#### Version

v1.5.9

### Steps to reproduce


- Press 'Ctrl + j' or 'alt + j' or 'cmd + j' to open wallet details window > check to include private keys > copy to clipboard
- Press 'Ctrl + g' or 'alt + g' or 'cmd + g' to open manual payout tool
- Press 'Ctrl + e' or 'alt + e' or 'cmd + e' to open BTC emergency wallet tool for both BTC and BSQ - did not want to try it but assume no password needed to send funds?

### Expected behaviour

When user has wallet password enabled password prompt is shown when doing the above 3 actions

### Actual behaviour

When user has wallet password enabled no password prompt is shown when doing the above 3 actions.  Funds can be send without password.


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/bisq-network/bisq/issues/5276
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.bisq.network/pipermail/bisq-github/attachments/20210305/92b2a9f6/attachment.htm>


More information about the bisq-github mailing list