PIP 26 could lead to pascal coin hacks via url/simple clicks on webpages.

Started by Skybuck, April 04, 2019, 11:22:57 PM

Previous topic - Next topic

Skybuck

PIP-0026 is to be avoided as well, like PIP 27 and PIP 28.

First it's unclear how to fast set of unicode characters would translate to pascal coin limited set of characters, is there a possibility of deceptions by using strange unicode characters ?!

But more alarmingly this would introduce more "parsing" technology at the click of a link.

Reminds me of webbrowser security bugs and all kinds of other mischiefs with links.

Such a feature could be introduce into a seperate wallet where security is of less importance and users can then decide to run an "ultra secure" pascal coin client without any or too much "parsing junk" in it or a less secure wallet which could be "hacked by parsing mistakes".

If integrated into the main wallet/main pascal coin software then at the very least there should be a "security option" to disable any form of parsing.

Including URI parsing and JSON parsing in the event of a code/hack/breach of security inside these technologies.

This would allow users to de-active these features inside pascalcoin when such a security risk/breach event occurs.