core icon indicating copy to clipboard operation
core copied to clipboard

Add Paradigm hotlist

Open samczsun-paradigm opened this issue 3 years ago • 5 comments

PR Title

Add Paradigm hotlist

Description

Adds the Paradigm hotlist to the list of phishing endpoints to check. This hotlist will be updated manually during security incidents, almost always by me personally.

  • ADDED:

    • New endpoint to PhishingController

Checklist

  • [x] Tests are included if applicable
  • [x] Any added code is fully documented

samczsun-paradigm avatar Oct 01 '22 06:10 samczsun-paradigm

Thanks for the PR, Sam! I added some tests and fixed some linting issues making it ready for review!

I wonder if we would prefer the Paradigm hotlist only including blacklist, similarly to the Phishfort list 🤔 Since changes to the fuzzylist has big implications for the functionality of the entire system.

cc @Gudahtt @409H

FrederikBolding avatar Oct 03 '22 11:10 FrederikBolding

Thanks! Was meaning to get to the failing tests after I pushed out the project I was working on, but I see it probably would've taken a bit of time without any context.

I'm open to only including the blacklist if that would make things easier.

samczsun-paradigm avatar Oct 05 '22 18:10 samczsun-paradigm

I agree with @FrederikBolding ; that would be much easier for us to manage. The fuzzylist has a high false-positive rate so we have to be very careful about expanding that.

Also, where should we direct users that want to dispute an entry on your list? We include a dispute link on our warning page, so we need one for each list. We use our eth-phishing-detect repo for disputes, and drop them straight into a partially-filled-out issue template. But a "contact" page or something would work too.

Gudahtt avatar Oct 05 '22 19:10 Gudahtt

Updated. As for the redirect link, maybe the issues page too then.

samczsun-paradigm avatar Oct 05 '22 19:10 samczsun-paradigm

Ah, that lint took a long time to fail. Will check it out. (e: seems like it's flakey?)

samczsun-paradigm avatar Oct 05 '22 20:10 samczsun-paradigm

@samczsun-paradigm Looks like this needs a rebase after some changes were made to the PhishingController.

FrederikBolding avatar Oct 26 '22 10:10 FrederikBolding