Bitcoin Forum
June 28, 2024, 03:50:17 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: MetaMask Allegedly Not Fixing Privacy Vulnerability  (Read 109 times)
pushups44 (OP)
Sr. Member
****
Offline Offline

Activity: 854
Merit: 281


View Profile
February 03, 2022, 10:34:39 PM
Last edit: February 03, 2022, 10:50:33 PM by pushups44
 #1

From Crypto Briefing: https://cryptobriefing.com/ethereum-wallet-metamask-has-critical-privacy-vulnerability/

"A cryptographer and security analyst has revealed how MetaMask users are at risk of exposing their IP address to hackers."

[...]

"Lupascu found that malicious entities can find MetaMask mobile users' IP data by airdropping them NFTs."

[...]

"By default, the MetaMask mobile app displays NFTs stored in an address using a URL function call to the image data. This data is hosted on remote servers. The process is done without asking for the user’s consent in order to display what NFTs are contained in their Ethereum wallet.

"During this fetching process, all server gateways handling the transmission of image data receive the user’s IP information. Generally, the projects operating the servers for the image data keeps the data secure.

"In his investigation, Lupascu determined that malicious entities can find MetaMask users’ IP data and exploit the information to execute targeted attacks. In his blog post, Lupascu explained:

“If a malicious actor only knows your blockchain address, he can mint an NFT with a URL pointing to his server and transfer the NFT’s ownership to your address. Thus, when your crypto wallet fetches the remote image from the server, it will compromise your privacy.”

[...]

"Meanwhile, Lupascu says that he thinks Ethereum users should be vigilant if they receive airdropped NFTs, and that it’s advisable to only access them through OpenSea."
coupable
Hero Member
*****
Offline Offline

Activity: 2408
Merit: 757


View Profile
February 03, 2022, 11:02:24 PM
Last edit: February 04, 2022, 01:41:26 PM by coupable
 #2

Using a navigator extension is your main vulnerability if you are already doing it.
I have noticed that people are not aware using such services like they are blindly trusted. Navigator addons weren't an advisable method for accessing online platforms although it's maybe a safe tool to interact with the Ethereum network.

"Meanwhile, Lupascu says that he thinks Ethereum users should be vigilant if they receive airdropped NFTs, and that it’s advisable to only access them through OpenSea."
Same thing with using opensea as a trusted network while we saw haw many vulnerabilities this system has encountered recently .
hugeblack
Legendary
*
Offline Offline

Activity: 2562
Merit: 3780


View Profile WWW
February 04, 2022, 08:50:03 AM
 #3

What's new here? Most of the users of MetaMask have a preliminary knowledge and therefore at one point or another they can be traced easily and thus leaking the IP address will be easy.
Even in Bitcoin, unless you administer a full node, some may be able to determine your IP address.

Using a reliable VPN and connecting to Tor will enhance your privacy, but MetaMask wallet does not focus on privacy as much as the ease of managing the wallet.

NFT Ethereum gas are also expensive, so these attacks cannot be random, but rather part of a social attack.
YOSHIE
Legendary
*
Offline Offline

Activity: 2156
Merit: 1776



View Profile
February 04, 2022, 09:32:03 AM
 #4

"Lupascu found that malicious entities can find MetaMask mobile users' IP data by airdropping them NFTs."
How about those who use MetaMask only to exchange tokens to USDT or BNB, without accessing the NFT feature, is it still being detected IP, only using it as an exchange and transaction. safe or not.

Yes, maybe from their side, their MetaMask should immediately fix the features as you said related to NFT, for security and avoid bad things, we all know like opensea etc, the NFT sales market is always connected to the ETH wallet, I think it should be resolved as soon as possible, I often see the assets of people who sell NFT up to thousands of $ which are stored and traded on the opensea market.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
Findingnemo
Hero Member
*****
Offline Offline

Activity: 2380
Merit: 795


Bitcoin = Financial freedom


View Profile
February 04, 2022, 11:38:59 AM
 #5

No matter for what kind of airdrop and bounty rewards it is preferable to have a secondary wallet so you can avoid exposing your primary wallet balance. This is more of a privacy issue not related to security of our wallet but Metamask should act fast and resolve the things with possible solutions.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
View ArchiveReport to moderator
martyMC
Member
**
Offline Offline

Activity: 159
Merit: 11


View Profile
February 05, 2022, 07:57:42 AM
 #6

From Crypto Briefing: https://cryptobriefing.com/ethereum-wallet-metamask-has-critical-privacy-vulnerability/

"A cryptographer and security analyst has revealed how MetaMask users are at risk of exposing their IP address to hackers."

[...]

"Lupascu found that malicious entities can find MetaMask mobile users' IP data by airdropping them NFTs."

[...]

"By default, the MetaMask mobile app displays NFTs stored in an address using a URL function call to the image data. This data is hosted on remote servers. The process is done without asking for the user’s consent in order to display what NFTs are contained in their Ethereum wallet.

"During this fetching process, all server gateways handling the transmission of image data receive the user’s IP information. Generally, the projects operating the servers for the image data keeps the data secure.

"In his investigation, Lupascu determined that malicious entities can find MetaMask users’ IP data and exploit the information to execute targeted attacks. In his blog post, Lupascu explained:

“If a malicious actor only knows your blockchain address, he can mint an NFT with a URL pointing to his server and transfer the NFT’s ownership to your address. Thus, when your crypto wallet fetches the remote image from the server, it will compromise your privacy.”

[...]

"Meanwhile, Lupascu says that he thinks Ethereum users should be vigilant if they receive airdropped NFTs, and that it’s advisable to only access them through OpenSea."
""Meanwhile, Lupascu says that he thinks Ethereum users should be vigilant if they receive airdropped NFTs, and that it’s advisable to only access them through OpenSea.""
What do they mean exactly? I thought Metamask was mandatory to access to Opensea. AFAIK you can't access to Opensea without a walletconnect software so it will be hard to do such thing. Besides that, I don't understand why Metamask is still only unavailable through a plugin for browser a standalone application would be way more secure IMO
vv181
Legendary
*
Offline Offline

Activity: 1932
Merit: 1273


View Profile
February 05, 2022, 11:58:42 AM
 #7

What do they mean exactly?
Browsing NFTs within a Metamask poses a risk of your privacy being compromised. The difference is opening up/browsing the NFT on Metamask may leak your IP since your device(Metamask) are directly communicating with the NFT image of the server, on another hand, if you browse it up on Opensea, the concern will be invalid.

You can see this article to see in full detail: Critical privacy vulnerability — getting exposed by MetaMask

I thought Metamask was mandatory to access to Opensea. AFAIK you can't access to Opensea without a walletconnect software so it will be hard to do such thing.
Yes, but it also technically can be accessed directly without Metamask or any wallet.
fullhdpixel
Hero Member
*****
Offline Offline

Activity: 2856
Merit: 612



View Profile
February 07, 2022, 10:11:41 AM
 #8

No matter for what kind of airdrop and bounty rewards it is preferable to have a secondary wallet so you can avoid exposing your primary wallet balance. This is more of a privacy issue not related to security of our wallet but Metamask should act fast and resolve the things with possible solutions.
Hackers in the crypto field are not picky but they will hack all accounts here as long as they can no matter how much is the users balance because small amounts can add up making the value larger but I like the suggestion that you said. Often times I receive scam coins from a random address, I sometimes wonder how did they do that but I realize that anyone can see the address that I posted in the forms when I apply for bounties and airdrops.

This isn't just a privacy matter but our security is also at risk here. Clicking on the links associated to that coin or NFT that they sent can lead you to a phishing site which can empty your account.

       ███████████████▄▄
    ██████████████████████▄
  ██████████████████████████▄
 ███████   ▀████████▀   ████▄
██████████    █▀  ▀    ██████▄
███████████▄▄▀  ██  ▀▄▄████████
███████████          █████████
███████████▀▀▄  ██  ▄▀▀████████
██████████▀   ▀▄  ▄▀   ▀██████▀
 ███████  ▄██▄████▄█▄  █████▀
  ██████████████████████████▀
    ██████████████████████▀
       ███████████████▀▀
.
.Duelbits.
.
..THE MOST REWARDING CASINO......
   ▄▄▄▄████▀███▄▄▄▄▄
▄███▄▀▄██▄   ▄██▄▀▄███▄
████▄█▄███▄█▄███▄█▄████
███████████████████████   ▄██▄
██     ██     ██     ██   ▀██▀
██ ▀▀█ ██ ▀▀█ ██ ▀▀█ ██    ██
██  █  ██  █  ██  █  ██
█▌  ██
██     ██     ██     ████  ██
█████████████████████████  ██
████████████████████████████▀
█████████████████████████
█████████████████████████
████████████████████████▌
       +4,000       
PROVABLY FAIR
GAMES
   $500,000   
MONTHLY
PRIZE POOL
      $10,000     
BLACKJACK
GIVEAWAY
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!