Aman Dhesi
@aman
It's a common misconception that just simulating transactions will keep you safe from losing your crypto! Simulation only works for transactions, not for signatures. Most attacks these days are happening through Seaport signatures and it will only get worse with Uniswap permit2.
5 replies
0 recast
0 reaction
dimalaba.eth
@dimalaba.eth
Signatures should have explicit domain field as in siwe Then wallets can show warning if there’s mismatch
1 reply
0 recast
0 reaction
Aman Dhesi
@aman
Domain as in url? or something else?
1 reply
0 recast
0 reaction
dimalaba.eth
@dimalaba.eth
Yes - it should make it harder to get signature for Opensea from 3rd website Ideally if the signature is very scoped down and there’s a common standard - wallets can automatically validate it
1 reply
0 recast
0 reaction
Aman Dhesi
@aman
Yes agreed that signatures need to be scoped down but i'm not sure scoping based on domain is a good idea. Any website should be able to interact with seaport! Many marketplaces use it already
2 replies
0 recast
0 reaction
dimalaba.eth
@dimalaba.eth
Yeah if it’s for protocol domains aren’t great. Some kind of protocol identifier?
0 reply
0 recast
0 reaction