Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[0] Add Scam Alert #2529

Closed
bangzi1001 opened this issue Mar 13, 2019 · 12 comments
Closed

[0] Add Scam Alert #2529

bangzi1001 opened this issue Mar 13, 2019 · 12 comments
Assignees
Milestone

Comments

@bangzi1001
Copy link
Contributor

@bangzi1001 bangzi1001 commented Mar 13, 2019

Is your feature request related to a problem? Please describe.
Lot of scam going around Bitshares DEX causing lot of users losing money and also also reputation of Bitshares. The reason users get scammed easily because the reference UI and gateway UI does not deliver the message to users until they get scammed and then come to Telegram to see what is happening.

Describe the solution you'd like

  1. Scam Alert via Popup Message when users open reference wallet wallet.bitshares.org or gateway UI. Describe what is happening and how to prevent it. This does not limited to proposal scam because scammer will change to different method once it become useless. If users are well informed, then the damage will be zero or minimal.
  2. A "SCAM ALERT" Menu beside REPORT and HELP.
@grctest

This comment has been minimized.

Copy link
Contributor

@grctest grctest commented Mar 13, 2019

I think a popup or extra steps required to transfer ownership of your account in a proposal is appropriate, but a generic scam warning could be too broad to prevent users from falling for such scams.

@bangzi1001

This comment has been minimized.

Copy link
Contributor Author

@bangzi1001 bangzi1001 commented Mar 13, 2019

The proposal scam is sophisticated social engineering attack, thus even the UI add extra 3-5 steps also meaningless for users who are not aware it is a scam. What users see is security upgrade which is required and then they just press the buttons.

Information is Power. The scam Alert via Popup Message is the best way to inform and educate the users what kind of scam is happening now and thus even they see the proposal or any scam attempt, they can avoid it. If they don't, then they only can blame themselves.

Last but not least, "popup or extra steps required to transfer ownership of your account in a proposal " only prevent one type of scam, the proposal type scam. But "scam Alert via Popup Message" able to prevent different type of scams as soon as it happen, the UI able to alert all users when they open the wallet.

@grctest

This comment has been minimized.

Copy link
Contributor

@grctest grctest commented Mar 13, 2019

Who would have the power/authority to distribute these popup messages? If they dismiss the message without reading it will they see it again if they encounter a scam situation?

I think that if they're informed that by transferring their account keys/ownership to someone else that it's an irreversible action & that nobody from bitshares/gateways will ever ask them to do this and for them to go through an extra hoop or two may be enough to stop this one type of scam from being successful again in the future. That said, you're right that some people will blindly click but that's then their own fault.

@sschiessl-bcp

This comment has been minimized.

Copy link
Contributor

@sschiessl-bcp sschiessl-bcp commented Mar 22, 2019

What is the idea on the scam alert?

Should:

  • the UI recognize that something scammy is going on by itself and do a warning?
  • the UI connect to for example a dedicated github repositories where scam alerts can be pushed that will then be shown once in UI?
@bangzi1001

This comment has been minimized.

Copy link
Contributor Author

@bangzi1001 bangzi1001 commented Mar 22, 2019

"the UI connect to for example a dedicated github repositories where scam alerts can be pushed that will then be shown once in UI?"

Something like this but only UI team(to prevent misuse by others) able push scam alert that show on UI. Not once but probably few times or a period of time.

@bangzi1001

This comment has been minimized.

Copy link
Contributor Author

@bangzi1001 bangzi1001 commented Apr 10, 2019

Proof that 3-4 clicks won't prevent Bitshares witness get scammed. How about normal users?

2019-04-10_23h26_03a

@abitmore

This comment has been minimized.

Copy link
Member

@abitmore abitmore commented May 4, 2019

@bangzi1001

This comment has been minimized.

Copy link
Contributor Author

@bangzi1001 bangzi1001 commented May 9, 2019

Just saw Openledger warn users with this method. It is simple but effective.
2019-05-10_01h24_03

@sschiessl-bcp

This comment has been minimized.

Copy link
Contributor

@sschiessl-bcp sschiessl-bcp commented May 10, 2019

Just saw Openledger warn users with this method. It is simple but effective.
2019-05-10_01h24_03

In the pipeline for next release #2679

@sschiessl-bcp

This comment has been minimized.

Copy link
Contributor

@sschiessl-bcp sschiessl-bcp commented Sep 24, 2019

@bangzi1001 does the solution of #2679 satisfy your needs described?

@blincadmin

This comment has been minimized.

Copy link

@blincadmin blincadmin commented Sep 27, 2019

Excellent addition to the UI

@sschiessl-bcp

This comment has been minimized.

Copy link
Contributor

@sschiessl-bcp sschiessl-bcp commented Sep 27, 2019

Thanks, closing this now, done.

@sschiessl-bcp sschiessl-bcp added this to the 190927 milestone Sep 27, 2019
@sschiessl-bcp sschiessl-bcp changed the title Add Scam Alert [0] Add Scam Alert Nov 4, 2019
@sschiessl-bcp sschiessl-bcp self-assigned this Nov 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
5 participants
You can’t perform that action at this time.