Content pfp
Content
@
https://ethereum.org
0 reply
0 recast
0 reaction

polymutex pfp
polymutex
@polymutex.eth
You use Chrome. Imagine for a moment that Chrome sent š™šš™«š™šš™§š™® š™š™š™‡ š™®š™¤š™Ŗ š™«š™žš™Øš™žš™©š™šš™™ to Google. That would be outrageous, right? web3 is about doing better than this. Well, what if your wallet did the very same thing? šŸ‘‡
3 replies
5 recasts
42 reactions

polymutex pfp
polymutex
@polymutex.eth
The above screenshot is a network capture of a popular browser extension wallet. Which wallet is in the screenshot? That's not important.š—£š—暝—²š˜š˜š˜† š—ŗš˜‚š—°š—µ š—®š—¹š—¹ š˜„š—²š—ÆšŸÆ š˜„š—®š—¹š—¹š—²š˜š˜€ š˜„š—¼š—暝—ø š˜š—µš—¶š˜€ š˜„š—®š˜†. That needs to change.
1 reply
1 recast
12 reactions

polymutex pfp
polymutex
@polymutex.eth
š™’š™š™® š™¬š™¤š™Ŗš™”š™™ š™¬š™–š™”š™”š™šš™©š™Ø š™™š™¤ š™©š™š™žš™Ø? UX. Wallets need to fetch token balances etc. This leaks your Ethereum address. But... why also leak the site you are visiting? Wallets want to check if the URL you are on is a known scam site. They snitch the URL by doing so.
1 reply
0 recast
5 reactions

polymutex pfp
polymutex
@polymutex.eth
š™„š™Ø š™©š™š™šš™§š™š š™– š™—š™šš™©š™©š™šš™§ š™¬š™–š™®? Yes. Chrome warns you when you are about to visit a scam website as well (a feature called "Safe Browsing"), yet does not leak every URL you visit to Google.
1 reply
0 recast
5 reactions

polymutex pfp
polymutex
@polymutex.eth
š™ƒš™¤š™¬ š™™š™¤š™šš™Ø š™žš™© š™™š™¤ š™©š™š™žš™Ø? It hashes the domain part of the URL, pick the first few bytes, and retrieves a list of domains whose first few bytes are the same. It retrieves this list through an anonymizing proxy. Google doesn't learn your IP, nor the site you visited.
1 reply
0 recast
8 reactions

polymutex pfp
polymutex
@polymutex.eth
(Caveat: Chrome has an alternative feature called "Enhanced Safe Browsing" which š—±š—¼š—²š˜€ leak the full URL you are visiting to Google.) (Don't use it.)
1 reply
0 recast
5 reactions

polymutex pfp
polymutex
@polymutex.eth
š™’š™–š™”š™”š™šš™©š™Ø š™˜š™–š™£ š™™š™¤ š™©š™š™š š™Øš™–š™¢š™š. A wallet should š™£š™¤š™© leak more than one of the following at once: 1ļøāƒ£ Your IP addres. 2ļøāƒ£ Your Ethereum address 3ļøāƒ£ The URL you are visiting The technology to avoid leaking this exists. Just a matter of execution.
1 reply
0 recast
9 reactions