The app does not have the ability to sign transactions on your behalf without your explicit approval.
The app does not have the ability to sign transactions on your behalf without your explicit approval.
It's used by a lot of DeFi apps, often with an unlimited amount. It doesn't give control of the tokens to a website, but rather to a contract. It's fine if the contract is secure and immutable, but of course that's not always the case.
It is easy to create a site that asks you to provide your wallet private phrase. The DNS MyEtherWallet hack that I vaguely recall exploited this.
On the other hand, good crypto citizens will just use the web3 library that will request permissions on an ad-hoc basis from your wallet extension (such as MetaMask).
However even then you can scam someone using social engineering: Just tell them "how" to do XYZ. E.g. "To get your free mini-monkey NFT, just connect your wallet with your bored ape, and when the confirm box pops up from metamask just click OK".
The fiat equivalent of course is a site that asks you to log into paypal and send them $1000 - but that is way more obvious than the crypto equivalent, where you interact with a smart contract and it isn't necessary clear ahead of time what will happen. Especially as smart contracts might be used for, for example user registration. If the user registration endpoint asks for money then you could get scammed that way.
When a site initiates a transaction, you can see the address you're interacting with. You should then look up the address on etherscan to see if it has public code and a lot of transactions. Then you should search that address in google and see if the main site links to it. A lot of projects have a list of addresses in their github. You can also inspect the function code. Once you're comfortable, you should add it to your saved addresses on your wallet and next time you'll see the name of the address.
Also you can create a new throw away address, transfer just a little bit of coins to it and interact with the contract. If it does what you think it should do, then you can create a new account and do it again.
It's not perfect. It could be a proxy, so you're not guaranteed the contract you're interacting with.
There's no easy way to "see what a transaction does". You just need to do risk management.
Oh, that’s it? So simple.
I wish wallets made it easier to create a burner throw away account or there were some trusted contracts that would create an account, do something and then transfer back to another account. I don't know if anything like that exists or even if the workflow is generalizable enough
How much money would you be spending on this scheme (in transaction fees)?
(let's keep the discussions civil)
The only thing I can imagine you’re talking about is when some wannabe domestic terrorists rightfully had their funding declined.
Crypto seems like a convenient way to do this, and the more repressive governments get, the more of a use-case there'll be!
https://www.savings.com.au/news/scamwatch-2021
Australians lost a record $323 million to scams in 2021
--
So glad they solved fraud prevention 'decades ago'.
But in the regular banking system we have decades of experience in how to mitigate the impacts of them e.g. account insurance, MFA for any new transfers or over a certain limit, auditing by independent regulators.
The tech community should be keenly aware of this because there are new apps, new languages, new libraries, new plugins, etc all the time, which solve a problem that was pretty much solved already.
You might counter that new things usually have to have some value proposition to gain a footing, like cheaper, faster, more reliable, etc. For one, that's not always true, but also crypto does have a value proposition like that. It's immutable, trustless, and can be anonymous. And it is even cheaper and faster than the regular banking system in some circumstances, depending on the sum being sent and where it goes.
This is a well known fact in secure system design. Most people just click through dialogs. If you must get their attention you have to make the dialog huge and scary but then people will usually just turn back instead of reading. Scary dialogs make it seem like you should never say OK.
“Undo” is powerful in any app, not just because it can roll a change back with a single click, but because scary dialog boxes (“Really, really REALLY delete this file? It can not be recovered once deleted, so check this box saying you know what you’re doing before clicking OK”) don’t work for regular apps, either.
Always someone getting burned, but in this case it's the "idiots" for lack of better word. Don't try to make cryptocurrencies work like fiat, that's exactly the kind of problems they're trying to solve.
And let's say someone implements your solution, years later you will read how a bad actor did a chargeback for all the coins in those contracts and you will claim it was a retarded feature from the start.
You didn't even explore any of the options for different types of "undo" operations that could be possible in contracts. You seemed to simply assume recreating the exact same situation that exists in traditional finance and responded based on that.
There are several other ways of doing it that I can think of, all with their own pros and cons. There are even a couple that have already been applied in crypto that I can think of and I'm sure many that I'm not aware of.
And why would you assume I even meant "reimplement traditional chargebacks as they are today"? My recommendation: Hold off on forming strong opinions too early in the process of learning about something.
So it's safest to just avoid debit cards, unless you know that the issuer has their own legally-binding limits on cardholder liability.
If entered, the transaction happens on the Maestro et. al. network and you can’t do chargebacks.
If no PIN was entered, the transaction happens on Visa/MC systems and you can chargeback.
Your bank irrespective of whether it's a savings account, credit card etc will almost always insure you against fraud provided you didn't do anything reckless e.g. write your PIN on the card.