nerd2ninja; ©️📺 on Nostr: This is the wallet? A software update is reloading the browser? There is no reverting ...
https://app.mutinywallet.com/This is the wallet? A software update is reloading the browser? There is no reverting versions because you disagree with the the new update, there is no verification before you load the new version (without special tooling). We just sorta hope the DNS server points to the IP its supposed to and that your webserver fingerprinting everyone's web browser isn't going to selectively rug pull.
I just thought this would be a file you download and then paste the file location into your web browser, I just assumed an expectation that a sandboxes browser like we have on f-droid that goes by that name would be the defacto suggestion for running this thing.
It was one thing to talk about web browser CVEs, but now we gotta talk about the web server getting a backdoor in it and selectively serving a different page based on fingerprinting information. You're killing me here!
Published at
2023-07-13 22:49:09Event JSON
{
"id": "6561cf08b0e574ed9e1ef56f2a638db4e8cda5875ae1ac4858658501224d0df6",
"pubkey": "834c0b53c8b33e0ad50fc4524e11f0506ac64fed2be7629e69512c9d2da74369",
"created_at": 1689288549,
"kind": 1,
"tags": [
[
"e",
"200c3b6ade53b4f71358e5f265f4ad8c3d2afd24a9548cc58ad20341677330ac",
"",
"reply"
],
[
"p",
"5be6446aa8a31c11b3b453bf8dafc9b346ff328d1fa11a0fa02a1e6461f6a9b1"
],
[
"p",
"834c0b53c8b33e0ad50fc4524e11f0506ac64fed2be7629e69512c9d2da74369"
],
[
"e",
"bb6f55f629d4bb4a17e8ba784a237f468d38f5663507ebd82d2540fcad3c8a14",
"",
"reply"
],
[
"p",
"5be6446aa8a31c11b3b453bf8dafc9b346ff328d1fa11a0fa02a1e6461f6a9b1",
""
]
],
"content": "https://app.mutinywallet.com/\n\nThis is the wallet? A software update is reloading the browser? There is no reverting versions because you disagree with the the new update, there is no verification before you load the new version (without special tooling). We just sorta hope the DNS server points to the IP its supposed to and that your webserver fingerprinting everyone's web browser isn't going to selectively rug pull. \n\nI just thought this would be a file you download and then paste the file location into your web browser, I just assumed an expectation that a sandboxes browser like we have on f-droid that goes by that name would be the defacto suggestion for running this thing. \n\nIt was one thing to talk about web browser CVEs, but now we gotta talk about the web server getting a backdoor in it and selectively serving a different page based on fingerprinting information. You're killing me here!",
"sig": "8536d42ff1037e578a2c7316a1dd3adca60ef14308413da719ee884061f16eacbbf9d975769f3bcc99083ed915d0d5cefe06cd6797ef24333e0663770522a134"
}