This doesn't look good. Still time to fix this, but I'm surprised there was no urgency even when they knew about it
After getting the above response, I asked the devs when the new version of the web wallet will be released. No response so far. I'll post here if I get any.
This needs to be fixed on an urgent basis. After what happened with Parity hack, I don't think I can sleep easy until this is fixed.
Shift also needs a desktop lite client. Web wallets cannot be trusted.
No answer about it yet ?
Hello,
One of the Shift devs responded on Ryver. I would like to share his response with you:
Some of you mentioned this post about a warning for LSK, SHIFT, RISE.
https://boards.4chan.org/biz/thread/2836956 There is no reason to panic, we are aware of that API endpoint and the security risk this could cause. They do have a point, and it is important to repeat: ALWAYS use the OFFICIAL https wallet, if you are not running your own node!
No need to say that we NEVER log input. Some users who lost their keys wish we would though.
We do have a fix for this, to be released in the next wallet update. Where we don't use this endpoint at all, and sign transactions at the client side to broadcast to our main nodes.
That way your private keys are safe, because they aren't sent at all. You can compare it to the way MyEtherWallet works.
We hope this explains the case and answers your questions.