Cointime

Download App
iOS & Android

ConsenSys Clears the Air on MetaMask Privacy Policy After Community Backlash

Ethereum infrastructure provider ConsenSys has issued a follow-up statement to its privacy policy update that rattled the MetaMask community last month.

The firm clarified that it does, in fact, collect users’ IP addresses and wallet information when they make a MetaMask transaction through Infura – but plans to reduce its retention of such data down to seven days.

Privacy Concerns at ConsenSys

Per the company’s statement on Tuesday, November’s policy update did not reflect a change in business practices at ConsenSys but rather served to clarify its existing practices. The update revealed that the company’s key products, MetaMask and Infura, collected both users’ wallet and IP addresses, raising privacy concerns.

https://twitter.com/CyphrETH/status/1595722882440642561

“We are committed to protecting the privacy of people who use our products so that they will not—and, ultimately, cannot—be betrayed by yet another centralized entity,” wrote ConsenSys.

Both MetaMask and Infura are pillars of the infrastructure that keeps Ethereum usable today. The former is the smart contract platform’s most widely used software wallet, while the latter is the API and archival node provider used by MetaMask for broadcasting transactions. Infura has also been used by various centralized exchanges like Binance and Bithumb when processing deposits and withdrawals.

As ConsenSys noted, its data collection policy comes with limits. For example, Infura does not store users’ wallet address data for ‘read’ requests, such as checking one’s account balance on MetaMask.

By contrast, wallet and IP data for “write” requests (transactions) are collected “to ensure successful transaction propagation, execution, and other important service functionality such as load balancing and DDoS protection, as provided by Infura.”

Still, ConsenSys said that wallet and IP address information is stored separately so that each piece of data cannot be associated with the other within the company’s systems.

“We have never and will never sell any user data we collect,” it continued.

Infura was one of the node providers to limit access to the privacy protocol Tornado Cash following OFAC’s sanctions against it in August.

Using Other Nodes

To work around the issue entirely, ConsenSys will roll out a new advanced settings page within MetaMask this week that allows wallet users to select their own RPC node provider outside of Infura. While previously possible, this new page will be seen by new users during the onboarding process, allowing them to never use Infura as their server if they so choose.

The company also plans to improve UX around the existing means for changing one’s RPC node, including making steps not to over-caution the user away from doing so.

Nevertheless, ConsenSys did have a certain warning about the practice of using non-default RPC nodes, including self-hosted nodes. “Alternate RPC providers have different privacy policies and data practices, and self-hosting a node may make it even easier for people to associate your Ethereum accounts with your IP address,” it said.

Ethereum archival nodes are recognized by the Ethereum foundation for generally being difficult to run for average users.

Comments

All Comments

Recommended for you

  • Hong Kong virtual asset spot ETF debuts today

    Today, six virtual asset spot ETFs were launched online in Hong Kong. The six virtual asset spot ETFs issued this time are from Huaxia (Hong Kong), Boshi International, and Jiashi International. The three institutions have certain differences in product fees, trading, issuance, and virtual asset platforms.

  • The total open interest of Bitcoin contracts on the entire network reached US$30.62 billion

    According to Coinglass data, the total open position of Bitcoin futures contracts on the entire network is 480,870 BTC (approximately $30.62 billion).

  • Over $734 million worth of PYTH is staked

    According to Dune data, there are currently 1,253,845,543 PYTH coins in a pledged state, with a total pledge value of $734,478,896. The number of PYTH pledgers has reached 159,165.

  • ConsenSys proposes four key reasons to support Ethereum's non-security status

    The US SEC's re-examination of whether Ethereum belongs to the securities category has caused controversy. ConsenSys has put forward four reasons to support Ethereum's non-securities status:

  • This week, Memecoin will unlock over $140 million worth of MEME at one time

    According to TokenUnlocks data, Memecoin will have a one-time large-scale token unlock this week, including:

  • Australian Stock Exchange Expects to Approve Spot Bitcoin ETF by the End of 2024

    According to a source who wishes to remain anonymous, Australia will follow in the footsteps of the United States and Hong Kong by launching a Bitcoin ETF. ASX Ltd., which handles about 80% of the country's stock trading, is expected to approve the first batch of spot Bitcoin ETFs on the main board by the end of 2024. A spokesperson for BetaShares, headquartered in Sydney, said in an interview that they are working to launch a product on the Australian Securities Exchange. Another local company, DigitalX Ltd., stated in its half-year results in February that it has applied. Justin Arzadon, the head of BetaShares' digital assets, said that the inflow of funds from the United States proves that digital assets will continue to exist. Arzadon added that the company has reserved ASX stock codes for spot Bitcoin and spot Ethereum ETFs.

  • A Superior Onboarding Experience: Overtime Markets Integrates Particle Network’s Wallet Abstraction

    Overtime Markets is a decentralized, permissionless sports market on the Arbitrum, Base and Optimism L2s. It’s developed on top of the Thales protocol, a permissionless, order book-based peer-to-peer Positional Markets platform powered by Chainlink price feeds.

  • SlowMist: Beware of watering hole attacks launched by malicious attackers using WordPress plugin vulnerabilities

    SlowMist Security has issued a warning that attackers have recently been exploiting vulnerabilities in WordPress plugins to inject malicious JS code into normal websites and launch watering hole attacks. These attacks involve popping up malicious windows when users visit the site, deceiving them into executing malicious code or performing Web3 wallet signatures, thereby stealing their assets. It is recommended that sites using WordPress plugins check for vulnerabilities, update plugins in a timely manner, and avoid being attacked. When visiting any website, users should carefully identify the downloaded programs and Web3 signature content to avoid downloading malicious programs or having their assets stolen due to malicious signatures.

  • Unverified Ember Sword NFT auction contract vulnerability has caused nearly $200,000 in losses

    Certik has discovered a vulnerability in the unverified Ember Sword NFT auction contract, which has earned 60 WETH (approximately $195,000) from 159 victims who approved the contract. Certik reminds users to revoke their approval of the relevant contract on Polygon.

  • Making Ether A Better Money

    In its current form, Ether (ETH) is not a good form of money. This is due to one critical limitation: its value is highly unstable. However, ETH can become stable by adjusting the rewards to validators (and thus the supply of ETH) to changes in demand for ETH. We can target a 0% inflation rate while ensuring validators are paid sufficiently to ensure network security. This new monetary policy can be called Stable Ether Monetary Policy (SEMP). With SEMP, ETH holders would have a great currency, and ETH validators would have exposure to the adoption of ETH.