Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable account unlock by default when node exposed via http #17023

Closed
ligi opened this issue Jun 18, 2018 · 1 comment
Closed

Disable account unlock by default when node exposed via http #17023

ligi opened this issue Jun 18, 2018 · 1 comment

Comments

@ligi
Copy link
Member

ligi commented Jun 18, 2018

We get a lot of reports like this: #17013

To mitigate this problem and protect users from harm unlocking of accounts should be disabled when:

  • the node is exposes via http
  • and the cli flag --iamawareoftherisks-allow-insecure-unlock is not given

context: this an chat by @holiman and @carver condensed into a github issue to keep track of it

@karalabe
Copy link
Member

This was shipped in 1.9.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants