Conversation
built with Refined Cloudflare Pages Action⚡ Cloudflare Pages Deployment
|
pinalikefruit
left a comment
There was a problem hiding this comment.
Hi @0xusmanf ,
Thanks you for the contribution.
I’m not entirely sure about this section, as many points, such as "Strong Password," "Antivirus Software," or "No Wallet Exposure on Calls" are already mentioned elsewhere in the framework. Regarding extensions, the "Minimal Auto-Lock Time" recommendation specifies a concrete value. The suggestion to use a dedicated profile is sound good, and there is no need to recommend additional extensions solely for interacting with dApps.
Since many of these recommendations are repeated in other parts of the framework, I think the "Key Considerations & Trade-offs" section could be improved instead.
|
Hi @pinalikefruit, thank you for the review and feedback. 1- Strong Password: Agreed, but instead of removing it completely, I'd link it to the relevant section since it's in a different framework.
I'm not sure what you meant here; could you please clarify? Regarding putting them under Key Considerations & Trade-offs, happy to do that, but in my opinion, this section is more about risk awareness, and the Security Best Practices section is about minimizing risk. |
|
Fair enough @0xusmanf , I see your point, you can leave it as "Security Best Practices." I would focus on adding as much value as possible to the "Security Best Practices" section regarding hot wallets for example , recommending a dedicated device (like a $200 laptop) solely for using the hot wallet. I wouldn't recommend installing anything else, no extra browser extensions, antivirus software, or other apps etc. |
Good point; I was thinking of adding it as a separate section, Software Wallets on Air-Gapped Devices, which sits between a hot wallet and a cold wallet. Hot wallets and Software Wallets on Air-Gapped Devices both have different risk profiles, so it is important to keep them separate to avoid any confusion. Since people are going to use hot wallets on their primary devices anyway, what I would do is keep the Security Best Practices section as is and add Software Wallets on Air-Gapped Devices separately. I’d love to get your thoughts on this approach. Does that structure make sense to you? |
|
Exactly; the idea is not to repeat the same information on every page, but rather to try to provide maximum value on each one. Speaking of Curious to know what you’re proposing and the best way to fit the information in. |
|
Thanks for sharing those links, @pinalikefruit! I agree there's baseline overlap in core hygiene (like minimal auto-lock timers and strong passwords) regardless of setup. To address this cleanly without overloading the beginner hot wallet guide:
I'll push the updates to the |
|
Yes, please; first add the contributions to this PR, and then we can continue with separate PRs. |
|
Hi @pinalikefruit, I have pushed the changes, kindly review. |
What does this PR change?
What changed
Added a Security Best Practices section to the hot wallet documentation (
docs/pages/wallet-security/for-beginners-and-small-balances.mdx), covering:0xusmanfto the list of document contributors alongsidepinalikefruit.Why
To provide actionable guidelines for users storing funds in hot wallets, helping them protect their keys from malware, unauthorized browser extension access, and social engineering attacks during screen shares.
Hi @pinalikefruit, could you please review these changes when you have a chance? Thanks!
Type of change
If applicable
vocs.config.tswith thedev: trueparameterStuck on anything? Just write it here and we're happy to help.