Skip to content

Conversation

douglasbakkum
Copy link
Member

MyEtherWallet redid their website and put the old version of MEW at vintage.myetherwallet.com.

In addition, the 'hijack code' was changed from the U2F challenge parameter to the appId parameter, as the latter is a more stable representation of the website origin (for anti-phishing purposes). This was made apparent as the latest Chrome version changed how the challenge parameter was computed.

@douglasbakkum douglasbakkum force-pushed the 190227/u2fhijack_appid branch from 4bdbdb8 to 1795622 Compare March 4, 2019 13:03
@douglasbakkum douglasbakkum merged commit 1795622 into BitBoxSwiss:master Mar 4, 2019
douglasbakkum added a commit that referenced this pull request Mar 4, 2019
1795622 update u2f hijack whitelist for vintage MEW and latest Chrome (djb)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant