Content
@
0 reply
0 recast
0 reaction
EulerLagrange.eth
@eulerlagrange.eth
Was signing into a system with ETH wallet when I had a realization on security issues for SIWE in offchain systems. With smart contract wallets, login becomes a eth_call for 1271 sigs. It’s easy for me to run a forked node locally, and change the signer of a contract wallet to mine. If I’m alchemy, I can target the api key some backend uses, and swap out the node for mine. So now I can authenticate as another user. @ncitron.eth is right, we need /lightclients rpc nodes
1 reply
1 recast
12 reactions
Roberto Ruiz
@robertoruiz
That’s a solid point! I’m glad I took the time to read this.
0 reply
0 recast
0 reaction