create account

Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk! by ashaman

View this thread on: hive.blogpeakd.comecency.com
· @ashaman · (edited)
$107.97
Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!
This public service announcement is a reminder to **stay safe when you crypto!** I know many of you have heard this all before, I know I certainly have - but then the other day **I witnessed an attempted crypto-heist in the flesh,** so I feel it's worth saying it again in case anyone missed the memo.
![](https://steemitimages.com/DQmS8UkKnBe9p35uM6bzSGaa3T1LGn3CsigryQmLME7bhD5/image.png)

The other day I met up with an acquaintance of mine who is a miner, to have drinks and chat crypto. We only met recently, and hadn't had much time to talk tech until .then. Also, I was looking to sell some USD, so naturally we had our computers with us. 

A little bit of background: the individual I was meeting up with only got into crypto because it can be mined. In some ways, he might almos bet a caricature of what "chinese miners" are described as: he doesn't keep up with tech, he's not a technology enthusiast (other than crypto), he got involved because he can buy these machines that generate money as long as you keep them online.

He was also using an exchange as his wallet (for some cryptoassets), as not all cryptoassets have light wallets and some assets get acquired speculatively in quantities where its hard to justify the installation of a dedicated wallet for each one. I understand the line of reasoning, but I find it to be a path of least resistance that can be quite dangerous to follow.

When he fired up his browser, he immediately got a notification from his email about emails from Bittrex. I hear him say "Wtf? Someone's trying to withdraw my coins!" when he opens his email, and indeed, he has withdrawals awaiting approval in his email that he did not initiate. 

While he cancelled the withdraw requests, and changed his password on the exchange account, while my mind immediately jumped to attack vectors. How did this happen? The thought that it was a targeted attack because he is a miner crossed my mind, but didn't have much in support of it. It didn't seem likely that his PC was compromised/keylogged, or his exchange account would have been emptied for sure - but the attacker appeared thwarted by email 2FA.

The attack vector we determined was **password reuse across multiple sites**. He had used the same password on his the exchange as on various cryptocurrency oriented forums - which have disproportionately large targets painted on them for this very reason. One of the forums probably stored passwords insecurely (plaintext, or hashed without a salt), was hacked, giving attackers a DB of email addresses + passwords. From there, an attacker need only try the combination on exchanges.

My friend was very lucky on two counts - he didn't have the same password on his email and the attacker didn't have enough time, since the withdrawal attempts were discovered only 10-15 minutes after they were initiated. Given more time, the attacker could have run a background check (based on the KYC info in the exchange account), used the information from that to guess secret question answers, and reset his email password that way.

The way to protect yourself from the password reuse attack vector is by having a unique password for each and every online account. This can be accomplished by using a password manager, so instead of having to remember each and every password, you have one master passphrase which is necessary to decrypt your database of saved passwords. If you need to synchronize across multiple devices, as long as your master passphrase is strong, the password database can safely be stored in Dropbox/Google Drive. If you prefer to avoid sharing the encrypted DB with any 3rd parties, [syncthing](https://syncthing.net/) can be used.

I recommend [KeePass](http://keepass.info/) or [KeePassX 2](https://www.keepassx.org/) for a password manager. There are browser addons to allow autofilling of login information, but I would think twice about using those: is it really a good idea to give the software you use for executing untrusted code (your browser) direct access to the database of all your shared passwords?

Create a strong a pass-**phrase** for your password database.  Then, go to File->Database settings  (in KeePass2) or Database->Database settings (in KeePassX2), and increase the number of Itirations/Transform rounds. This will increase the amount of operations it takes to derive the DB's master keys from the password, making it much harder to decrypt via brute force attack.

KeePass2
![](https://steemitimages.com/DQmdqi62RQSzPjB7De4qEHt9Rv3FjhucSxypFnAnBS3Jeqy/image.png)

KeePassX2
![](https://steemitimages.com/DQmc46V7U86gxJXJWexiYwsqXHg4t9yrXJUK2xzFBt1uDMQ/image.png)

Then, every time you log in to an online account, you need to systematically start changing the passwords, replacing them wit ones randomly generated with KeePass. 

It is also of critical importance to enable 2FA on every cryptocurrency-related account where it is available, **including** email accounts associated with any logins. Google Authenticator is considerably more secure than Authy, but you have to make sure to write down 2FA secrets, as you will be locked out of your accounts without them if you lose your phone (or it breaks). 
[SMS-based 2FA is NOT secure](https://www.forbes.com/sites/laurashin/2016/12/20/hackers-have-stolen-millions-of-dollars-in-bitcoin-using-only-phone-numbers/#1eed67df38ba), and [should not be used](https://medium.com/@CodyBrown/how-to-lose-8k-worth-of-bitcoin-in-15-minutes-with-verizon-and-coinbase-com-ba75fb8d0bac). It is far too easy for an attacker to socially engineer the phone company into giving them control of your phone number.

**tl;dr Enable 2FA everywhere it's available and use a password manager, unless you want to make it easy for thieves to steal your hard-earned crypto. Don't use exchanges as wallets. Get a hardware wallet if its cost is <%10 of the value of the crypto you are holding and need to protect. Use traditionaly cold storage if you don't want to fork over the bitcents for a HW wallet.  Don't become a statistic.**
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 252 others
properties (23)
authorashaman
permlinkdo-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk
categorycryptocurrency
json_metadata{"tags":["cryptocurrency","bitcoin","bitshares","btc","bitcoincash"],"image":["https://steemitimages.com/DQmS8UkKnBe9p35uM6bzSGaa3T1LGn3CsigryQmLME7bhD5/image.png","https://steemitimages.com/DQmdqi62RQSzPjB7De4qEHt9Rv3FjhucSxypFnAnBS3Jeqy/image.png","https://steemitimages.com/DQmc46V7U86gxJXJWexiYwsqXHg4t9yrXJUK2xzFBt1uDMQ/image.png"],"links":["https://syncthing.net/","http://keepass.info/","https://www.keepassx.org/","https://www.forbes.com/sites/laurashin/2016/12/20/hackers-have-stolen-millions-of-dollars-in-bitcoin-using-only-phone-numbers/#1eed67df38ba","https://medium.com/@CodyBrown/how-to-lose-8k-worth-of-bitcoin-in-15-minutes-with-verizon-and-coinbase-com-ba75fb8d0bac"],"app":"steemit/0.1","format":"markdown"}
created2017-08-20 17:53:21
last_update2017-08-20 18:02:15
depth0
children53
last_payout2017-08-27 17:53:21
cashout_time1969-12-31 23:59:59
total_payout_value100.703 HBD
curator_payout_value7.264 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length6,043
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,367,467
net_rshares28,633,331,078,455
author_curate_reward""
vote details (316)
@adsactly ·
Great Post ... Thank you for sharing such valuable information... perhaps we would like we if you could join our discord channel https://discord.gg/TzasBp
properties (22)
authoradsactly
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184107286z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["https://discord.gg/TzasBp"],"app":"steemit/0.1"}
created2017-08-20 18:41:09
last_update2017-08-20 18:41:09
depth1
children1
last_payout2017-08-27 18:41:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length154
author_reputation1,627,695,460,224,226
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,029
net_rshares0
@ashaman ·
Joined the channel. Thanks for the invite!
properties (22)
authorashaman
permlinkre-adsactly-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t194254703z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 19:42:54
last_update2017-08-20 19:42:54
depth2
children0
last_payout2017-08-27 19:42:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length42
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,375,093
net_rshares0
@aguess ·
How can you explain in detail
properties (22)
authoraguess
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t183024743z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:30:18
last_update2017-08-20 18:30:18
depth1
children1
last_payout2017-08-27 18:30:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length29
author_reputation1,597,673,142,913
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,329
net_rshares0
@ashaman ·
For a more detailed explanation of how to set up KeePass, [there are many guides readily available](http://lmgtfy.com/?q=how+to+keepass).
properties (22)
authorashaman
permlinkre-aguess-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184700177z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["http://lmgtfy.com/?q=how+to+keepass"],"app":"steemit/0.1"}
created2017-08-20 18:47:00
last_update2017-08-20 18:47:00
depth2
children0
last_payout2017-08-27 18:47:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length137
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,426
net_rshares0
@alexanderrr ·
Are KeePassX databases encrypted just as KeePass DBs are? In other words, can I keep the KeePassX database file in Google Drive ~~without~~ with less fear? 

Noobie question, but I'm not very technical, and LastPass has become too much of a crutch for me. Would like to change my ways. Thanks for the advice/help!
properties (22)
authoralexanderrr
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170822t014535439z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-22 01:45:33
last_update2017-08-22 01:45:33
depth1
children2
last_payout2017-08-29 01:45:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length313
author_reputation8,409,842,191
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,490,438
net_rshares0
@ashaman ·
Yes. In fact KeePassX2 and KeePass databases are compatible with each other.
👍  
properties (23)
authorashaman
permlinkre-alexanderrr-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170827t072827346z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-27 07:28:27
last_update2017-08-27 07:28:27
depth2
children1
last_payout2017-09-03 07:28:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length76
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id13,002,641
net_rshares1,160,673,144
author_curate_reward""
vote details (1)
@alexanderrr ·
Good to know - thank you. Have been been trying to store everything in KeePassX2 as I log into accounts. Didn't realize how many accounts and passwords I had D:
properties (22)
authoralexanderrr
permlinkre-ashaman-re-alexanderrr-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170827t082829130z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-27 08:28:24
last_update2017-08-27 08:28:24
depth3
children0
last_payout2017-09-03 08:28:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length160
author_reputation8,409,842,191
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id13,005,916
net_rshares0
@andrejcibik ·
$0.17
Using last pass with 2FA is the best thing you can do! 
It safes time and your ass, because your security will be TOP.
👍  
properties (23)
authorandrejcibik
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181043024z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:10:42
last_update2017-08-20 18:10:42
depth1
children6
last_payout2017-08-27 18:10:42
cashout_time1969-12-31 23:59:59
total_payout_value0.172 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length118
author_reputation30,106,021,348,653
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,368,849
net_rshares46,008,327,725
author_curate_reward""
vote details (1)
@ashaman ·
I'm going to go ahead and urge everyone [**not** to use LastPass](https://www.hackread.com/lastpass-hacked-this-time-for-good/). They have been compromised in the past. With KeePass (even if you're using DropBox to sync multiple devices) the amount of surface area you leave exposed to possible attacks is way lower than with a service like LastPass - which is known to be a central location for login credentials of countless users.

I don't deny that LastPass has certain features with are a convenient, such as sharing login details for a specific account with other LastPass users, but you're trading convenience for security, which in the big picture has far too much in common with trading liberty for security: those who do it deserve neither, and will probably lose both.

If you have a Yubikey/Nitrokey or similar, it is possible to use it for 2FA in KeePass.
properties (22)
authorashaman
permlinkre-andrejcibik-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181806603z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["https://www.hackread.com/lastpass-hacked-this-time-for-good/"],"app":"steemit/0.1"}
created2017-08-20 18:18:06
last_update2017-08-20 18:18:06
depth2
children5
last_payout2017-08-27 18:18:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length868
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,369,403
net_rshares0
@andrejcibik ·
Only security questions where leaked. Im not concerned about that. My questions are worthless for attacker. 

Of I lose some security for ease of use, but still....I think lastpass with 2FA brings me 99.99% of security I can get. Just having different uncrackable pass on each site improves my sec drasticaly. 

I feel really secure against automated hacks (my email was compromised 2 times) and against targeted attack (jsut me) im hopeless anyways.
properties (22)
authorandrejcibik
permlinkre-ashaman-re-andrejcibik-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t183446368z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:34:45
last_update2017-08-20 18:34:45
depth3
children4
last_payout2017-08-27 18:34:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length450
author_reputation30,106,021,348,653
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,610
net_rshares0
@angela.ghkh ·
oh, thanks for your great suggest
i think i will try it out
upvoted dear
good luck with your security jobs ;)
properties (22)
authorangela.ghkh
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t204930858z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 20:49:36
last_update2017-08-20 20:49:36
depth1
children1
last_payout2017-08-27 20:49:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length109
author_reputation2,888,077,605,665
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,379,245
net_rshares0
@cornholio ·
http://i.imgur.com/yiHh8nA.gif
👍  
👎  
properties (23)
authorcornholio
permlinkre-angela-ghkh-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t204930858z-20170820t212735680z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"meep_bot/0.0.1"}
created2017-08-20 21:27:36
last_update2017-08-20 21:27:36
depth2
children0
last_payout2017-08-27 21:27:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length31
author_reputation606,749,206,056
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,381,437
net_rshares1,724,523,204
author_curate_reward""
vote details (2)
@arrkiin ·
Very good article. An emotional story out of real life is more convincing as all the other raw tech articles explaining possible attack vectors and solutions. Thank you for sharing your experiences.
properties (22)
authorarrkiin
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170822t121208318z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-22 12:12:09
last_update2017-08-22 12:12:09
depth1
children0
last_payout2017-08-29 12:12:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length198
author_reputation20,694,541,258
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,528,372
net_rshares0
@beautypics ·
UPVOTED.
very good.
I would be happy if you like to follow me and give your opinion about my posts.
Thanks.
properties (22)
authorbeautypics
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t203035857z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 20:30:36
last_update2017-08-20 20:30:36
depth1
children0
last_payout2017-08-27 20:30:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length107
author_reputation10,703,556,924,562
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,378,155
net_rshares0
@blackturtle ·
$0.08
Thats a quite important topic, thank you for telling us more about this. Your example was quite good, so it got more easier to understand the Problem. I although got the experience that KeePass is quite useful, you can even use it to generate passwords.

If you installed KeePass, don't forget to save the data of KeePass on a Stick or so, so the passwords are safe and protected before accidents like pc crash etc.
👍  
properties (23)
authorblackturtle
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t192833798z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 19:28:27
last_update2017-08-20 19:28:27
depth1
children1
last_payout2017-08-27 19:28:27
cashout_time1969-12-31 23:59:59
total_payout_value0.076 HBD
curator_payout_value0.006 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length415
author_reputation1,307,979,885
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,374,170
net_rshares22,152,157,793
author_curate_reward""
vote details (1)
@ashaman · (edited)
As long as you have as strong passphrase, the keepass DB can be safely sync'ed via cloud storage, since the data in it is encrypted. Alternatively, [Syncthing](https://syncthing.net/) can be used, allowing for cloud-less synchronization across multiple machines.
properties (22)
authorashaman
permlinkre-blackturtle-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t193624057z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["https://syncthing.net/"],"app":"steemit/0.1"}
created2017-08-20 19:36:24
last_update2017-08-20 19:36:30
depth2
children0
last_payout2017-08-27 19:36:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length262
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,374,679
net_rshares0
@celestialme ·
i don't care 2Fa  :D even steem asked me third time already pleasee dear user pleasee regenerate you password. :D
👍  
properties (23)
authorcelestialme
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t183612138z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:36:27
last_update2017-08-20 18:36:27
depth1
children0
last_payout2017-08-27 18:36:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length113
author_reputation234,898,823,983
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,713
net_rshares1,779,260,355
author_curate_reward""
vote details (1)
@cryptoclan ·
$0.17
Great post, but I have 1 question I hope you could answer.

What if you lose your phone with the 2FA on it? Is it easy to recover it?
👍  ,
properties (23)
authorcryptoclan
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t182211925z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:22:15
last_update2017-08-20 18:22:15
depth1
children4
last_payout2017-08-27 18:22:15
cashout_time1969-12-31 23:59:59
total_payout_value0.160 HBD
curator_payout_value0.013 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length133
author_reputation8,280,667,391
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,369,769
net_rshares46,415,462,656
author_curate_reward""
vote details (2)
@arrkiin ·
$0.06
If you are on android there is an, currently unreleased but usable, 2FA generator called "andOTP". In contrast to the mentioned Google Authenticator you can backup the entries with a strong password in an encrypted file. If you lost your phone you can install the app and restore it with the encrypted file. But don't forget the password :)

The app is available on the playstore and as well in the F-Droid store. If you are deeper in programming android or even java you can read the sourcecode on github as well or compile it on your own.

https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp

https://f-droid.org/packages/org.shadowice.flocke.andotp/

https://github.com/flocke/andOTP
👍  
properties (23)
authorarrkiin
permlinkre-cryptoclan-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170822t120741987z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp","https://f-droid.org/packages/org.shadowice.flocke.andotp/","https://github.com/flocke/andOTP"],"app":"steemit/0.1"}
created2017-08-22 12:07:42
last_update2017-08-22 12:07:42
depth2
children0
last_payout2017-08-29 12:07:42
cashout_time1969-12-31 23:59:59
total_payout_value0.047 HBD
curator_payout_value0.014 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length708
author_reputation20,694,541,258
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,528,088
net_rshares15,024,543,329
author_curate_reward""
vote details (1)
@ashaman ·
If you are using Authy, it backs up your keys on their servers - but this is less secure for obvious reasons.

For Google Authenticator, you need to back up the key when you set it up. Unless your phone is rooted, you have to make a backup of the QR code that you scan with your phone, or better yet, write down key provided along with the QR code.  On a rooted device, you can simply back Google Authenticator up with Titanium Backup (just make sure to backup your Titanium Backup folder to a device other than your phone, and be sure to encrypt the backup since the authenticator secret keys are backed up in cleartext).plain
👍  
properties (23)
authorashaman
permlinkre-cryptoclan-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184104325z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:41:03
last_update2017-08-20 18:41:03
depth2
children0
last_payout2017-08-27 18:41:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length627
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,025
net_rshares998,144,985
author_curate_reward""
vote details (1)
@mweddy · (edited)
it is not always easy like Bittrex gives 7 day trade ban on 2FA key recovery request and bitfinex also block ur activities for some time and u need to have SMS recovery.
👍  
properties (23)
authormweddy
permlinkre-cryptoclan-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184435200z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:44:36
last_update2017-08-20 18:45:06
depth2
children1
last_payout2017-08-27 18:44:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length169
author_reputation869,377,644
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,265
net_rshares974,932,311
author_curate_reward""
vote details (1)
@ashaman ·
If it was easy to reset a 2FA token at an exchange, it wouldn't offer any added security. You can avoid having to go through the process if you back up the 2FA secret when you set it up (it's encoded in the QR code you have to scan, and is generally provided in plain text along with the QR code).
👍  
properties (23)
authorashaman
permlinkre-mweddy-re-cryptoclan-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t233325898z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 23:33:24
last_update2017-08-20 23:33:24
depth3
children0
last_payout2017-08-27 23:33:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length297
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,388,451
net_rshares619,520,000
author_curate_reward""
vote details (1)
@cryptoeagle ·
$0.32
![index.jpg](https://steemitimages.com/DQmT6AHGanqg5ap9bNwkCjZ3Lhkx4vsA6ApLsprEzyv9Rvn/index.jpg)
I wish there was a way to enable 2FA here on Steemit. I understand it's complicated to do for posting and voting but for transfers it should be mandatory!
👍  , ,
properties (23)
authorcryptoeagle
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181233513z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"image":["https://steemitimages.com/DQmT6AHGanqg5ap9bNwkCjZ3Lhkx4vsA6ApLsprEzyv9Rvn/index.jpg"],"app":"steemit/0.1"}
created2017-08-20 18:12:33
last_update2017-08-20 18:12:33
depth1
children1
last_payout2017-08-27 18:12:33
cashout_time1969-12-31 23:59:59
total_payout_value0.314 HBD
curator_payout_value0.010 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length252
author_reputation34,365,374,648,965
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,368,979
net_rshares86,320,156,261
author_curate_reward""
vote details (3)
@ashaman ·
$0.12
It's non-trivial to do so because the only way the chain currently verifies a transaction's validity is by checking the digital signatures on the tx. While creating a 2FA mechanism for transfers on the steemit.com frontend interface would be easy it would in no way thwart an attacker who got control of an accounts private keys (they could just import the keys into cli_wallet and empty an account that way), without major changes to the backend. In order for a meaningful improvement in security, 2FA capability would have to be baked in to the STEEM blockchain. It's possible we'll see the addition of such a feature in a future hardfork someday.

IMO, hardware wallet support would do considerably more to ensure safety of high value accounts. I'm hoping 
 that once the BitShares Munich devs finish coding Ledger support for BTS it might get ported to STEEM. 

In the meantime what you can do is only perform transfer operations from a trusted device. On all other devices, log in with your posting private key in WIF format, rather than your password. It's also best practice to log in to various applications built on STEEM (ie. ChainBB for STEEM) with your posting private key, rather than your password.
👍  
properties (23)
authorashaman
permlinkre-cryptoeagle-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t182844810z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:28:45
last_update2017-08-20 18:28:45
depth2
children0
last_payout2017-08-27 18:28:45
cashout_time1969-12-31 23:59:59
total_payout_value0.090 HBD
curator_payout_value0.029 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,212
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,231
net_rshares32,135,282,420
author_curate_reward""
vote details (1)
@funkyronster ·
Thanks for the article. Would you regard the passwords generated and secured by Apples OSX Keychain facility as as good as a third party password manager?
properties (22)
authorfunkyronster
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170826t125903459z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-26 12:59:03
last_update2017-08-26 12:59:03
depth1
children2
last_payout2017-09-02 12:59:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length154
author_reputation0
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,932,008
net_rshares0
@ashaman ·
My only Apple product is a macbook that I have for the sole purpose of playing and producing music. I deliberately disabled iCloud and all their associated services. The word on the street is Apple take security seriously, so I'm inclined to say it can be used securely - as long as you're generating random unique 22+ character passwords for each and every account. That being said, I use KeePassX2 on my Macbook (pretty much purely for Soundcloud/Mixcloud logins). The only thing I use the OSX keychain for is locally stored wifi passwords.

My views, when it comes to security software - if it's not open source, it's not even in the running for something I would consider using. I may not have the skills to personally audit the code, but I (and/or others) could crowdfund a campaign to hire professionals to do it. I do not have that option for products that are proprietary, and in my book, Apple's (or any other company's) promise that their product is secure simply is not good enough without proper proof to back it.
👍  ,
properties (23)
authorashaman
permlinkre-funkyronster-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170827t072346646z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-27 07:23:45
last_update2017-08-27 07:23:45
depth2
children1
last_payout2017-09-03 07:23:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,025
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id13,002,381
net_rshares2,321,306,074
author_curate_reward""
vote details (2)
@funkyronster ·
Many thanks for the reply. Good luck!
properties (22)
authorfunkyronster
permlinkre-ashaman-re-funkyronster-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170827t111701779z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-27 11:17:00
last_update2017-08-27 11:17:00
depth3
children0
last_payout2017-09-03 11:17:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length37
author_reputation0
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id13,016,103
net_rshares0
@grizgal ·
$0.18
I still struggle to believe anyone uses exchanges to store large amounts.  Its not just the attack vectors but we have seen several exchanges disappear and another one looking like its on the verge of doing so.  2FA is also definitely the future.
👍  ,
properties (23)
authorgrizgal
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t183658159z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:37:00
last_update2017-08-20 18:37:00
depth1
children1
last_payout2017-08-27 18:37:00
cashout_time1969-12-31 23:59:59
total_payout_value0.134 HBD
curator_payout_value0.042 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length246
author_reputation2,658,909,943,160
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,751
net_rshares46,756,317,481
author_curate_reward""
vote details (2)
@ashaman ·
Exchanges have been hacked too. There were many who reasoned "I'm not a security expert, I'll probably be safer if I entrust Mt.Gox with storing my coins, since they obviously know what they're doing" and lost everything as a result.

Personally, I find it absolutely mind boggling that a majority of exchanges allow users to make deposits and trade without enabling 2FA first. So many thefts could be prevented if more exchanges dared to inconvenience their users by requiring 2FA to be enabled as a prerequisite for doing anything else.
properties (22)
authorashaman
permlinkre-grizgal-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t190056414z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 19:00:57
last_update2017-08-20 19:00:57
depth2
children0
last_payout2017-08-27 19:00:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length538
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,372,365
net_rshares0
@josepimpo ·
$0.16
I prefer Authy over Google Authenticator, saludos
👍  ,
properties (23)
authorjosepimpo
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170821t003646753z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-21 00:36:45
last_update2017-08-21 00:36:45
depth1
children1
last_payout2017-08-28 00:36:45
cashout_time1969-12-31 23:59:59
total_payout_value0.156 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length49
author_reputation220,544,762,312,113
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,391,586
net_rshares42,052,750,144
author_curate_reward""
vote details (2)
@ashaman ·
It's more convenient, for sure, but the way it binds to a phone number is a rather large lapse in security for the same reason SMS 2FA is insecure. Unless the choice isn't offered, I always select Google Authenticator over Authy.
👍  
properties (23)
authorashaman
permlinkre-josepimpo-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170821t004246722z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-21 00:42:48
last_update2017-08-21 00:42:48
depth2
children0
last_payout2017-08-28 00:42:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length229
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,391,908
net_rshares0
author_curate_reward""
vote details (1)
@kalistacking ·
$0.28
Good Stuff man I try to tell people all the time there is no such thing as 2 safe. double fire. offline/cold storage as much as possible. Resteemit this and the keepass is the best!
👍  , ,
properties (23)
authorkalistacking
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170822t184544380z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-22 18:45:48
last_update2017-08-22 18:45:48
depth1
children0
last_payout2017-08-29 18:45:48
cashout_time1969-12-31 23:59:59
total_payout_value0.272 HBD
curator_payout_value0.005 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length181
author_reputation294,200,913,074
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,562,546
net_rshares66,964,851,970
author_curate_reward""
vote details (3)
@khalidharun ·
Blog is very useful for me who just joined in steemit
properties (22)
authorkhalidharun
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184009892z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:40:09
last_update2017-08-20 18:40:09
depth1
children0
last_payout2017-08-27 18:40:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length53
author_reputation263,629,267,286
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,945
net_rshares0
@luigizoloto ·
Great Post! Security and Privacy are two of the most important things when it comes to money. Don't risk it on a password manager.
👍  ,
properties (23)
authorluigizoloto
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t180541041z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:05:42
last_update2017-08-20 18:05:42
depth1
children0
last_payout2017-08-27 18:05:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length130
author_reputation28,232,984,903
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,368,416
net_rshares5,020,209,701
author_curate_reward""
vote details (2)
@mianfahad2 ·
nice post ... i upvoted you plz upvote me!!
👎  
properties (23)
authormianfahad2
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t183430087z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:34:33
last_update2017-08-20 18:34:33
depth1
children0
last_payout2017-08-27 18:34:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length43
author_reputation460,855,120,828
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,596
net_rshares-486,860,610
author_curate_reward""
vote details (1)
@mweddy ·
$0.12
I have lots of exchanges 2FA keys , API keys, it is very difficult to manage sometimes when u write those. I simply use my older smart phone i just take a snapshot of webpages for future recovery and i make sure this phone is never going to be connected to internet and is password protected. It is like having a nano ledger or keep key in low budget. i hope it is easier to recover in case i lost my main phone.
👍  ,
properties (23)
authormweddy
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184005777z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:40:06
last_update2017-08-20 18:40:06
depth1
children1
last_payout2017-08-27 18:40:06
cashout_time1969-12-31 23:59:59
total_payout_value0.099 HBD
curator_payout_value0.025 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length412
author_reputation869,377,644
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,370,942
net_rshares32,986,457,821
author_curate_reward""
vote details (2)
@ashaman ·
This is a perfectly valid backup mechanism for 2FA keys, I would still write the 2FA keys down though (or have some additional backup mechanism). The flash memory on the phone you use could fail at any time. 

Never forget that the golden rule for backups is `x=n-1`, where `x` is the number of copies of your data you have, and `n` is the number of independent storage devices you have copies stored on.
👍  
properties (23)
authorashaman
permlinkre-mweddy-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t185402477z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:54:03
last_update2017-08-20 18:54:03
depth2
children0
last_payout2017-08-27 18:54:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length404
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,892
net_rshares604,032,000
author_curate_reward""
vote details (1)
@randowhale ·
This post received a 4.2% upvote from @randowhale thanks to @ashaman!  For more information, [click here](https://steemit.com/steemit/@randowhale/randowhale-is-now-only-1-steem-sbd-per-vote-spread-the-news)!
properties (22)
authorrandowhale
permlinkre-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181131
categorycryptocurrency
json_metadata"{"app": "randowhale/0.1", "format": "markdown"}"
created2017-08-20 18:11:33
last_update2017-08-20 18:11:33
depth1
children0
last_payout2017-08-27 18:11:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length207
author_reputation47,657,457,485,459
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,368,904
net_rshares0
@ropname ·
Agree. Increasing your security is viable no only when dealing with crypo. Be smart in today's world where information is so important and when personal information is so at risk.
Cool post! Keep it up!
👍  
properties (23)
authorropname
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181915874z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:19:15
last_update2017-08-20 18:19:15
depth1
children0
last_payout2017-08-27 18:19:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length202
author_reputation430,944,109,138
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,369,495
net_rshares4,625,175,803
author_curate_reward""
vote details (1)
@steemitboard ·
Congratulations @ashaman! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

[![](https://steemitimages.com/70x80/http://steemitboard.com/notifications/votes.png)](http://steemitboard.com/@ashaman) Award for the number of upvotes

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click [here](https://steemit.com/@steemitboard)

If you no longer want to receive notifications, reply to this comment with the word `STOP`

> By upvoting this notification, you can help all Steemit users. Learn how [here](https://steemit.com/steemitboard/@steemitboard/http-i-cubeupload-com-7ciqeo-png)!
properties (22)
authorsteemitboard
permlinksteemitboard-notify-ashaman-20170821t004421000z
categorycryptocurrency
json_metadata{"image":["https://steemitboard.com/img/notifications.png"]}
created2017-08-21 00:44:21
last_update2017-08-21 00:44:21
depth1
children0
last_payout2017-08-28 00:44:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length684
author_reputation38,975,615,169,260
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,391,988
net_rshares0
@steemitboard ·
Congratulations @ashaman! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

[![](https://steemitimages.com/70x80/http://steemitboard.com/notifications/votes.png)](http://steemitboard.com/@ashaman) Award for the number of upvotes

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click [here](https://steemit.com/@steemitboard)

If you no longer want to receive notifications, reply to this comment with the word `STOP`

> By upvoting this notification, you can help all Steemit users. Learn how [here](https://steemit.com/steemitboard/@steemitboard/http-i-cubeupload-com-7ciqeo-png)!
properties (22)
authorsteemitboard
permlinksteemitboard-notify-ashaman-20170907t132944000z
categorycryptocurrency
json_metadata{"image":["https://steemitboard.com/img/notifications.png"]}
created2017-09-07 13:29:42
last_update2017-09-07 13:29:42
depth1
children0
last_payout2017-09-14 13:29:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length684
author_reputation38,975,615,169,260
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id14,150,485
net_rshares0
@stephenp888 ·
2FA is the way forward  i noticed my account had been logged into also  so i checked what the ip address was and it said it was an iphone that had logged in,  in germany... this is when i downloaded the 2fa or Google authenticator 
its brilliant
properties (22)
authorstephenp888
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170823t143229718z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-23 14:32:30
last_update2017-08-23 14:32:30
depth1
children1
last_payout2017-08-30 14:32:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length245
author_reputation-619,244,401
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,642,923
net_rshares0
@ashaman · (edited)
Did you reuse the password on that account anywhere else? Then that's the likely vector for how this was possible. However, if you can't establish an attack vector through which someone may have been able to do this, you have to seriously consider the possibility that one of your devices has been p0wned.
properties (22)
authorashaman
permlinkre-stephenp888-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170827t072703441z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-27 07:27:03
last_update2017-08-27 07:27:12
depth2
children0
last_payout2017-09-03 07:27:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length305
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id13,002,559
net_rshares0
@thisisit ·
$0.08
HOLLY COW!  This is why I have not bought any cryptos yet.  I want to know I am secure.  Lots of security solvers have come out but I want to wait a little longer.  I have come to the conclusion though, that keeping my wallet offline is the best solution.  I am contemplating a stand alone computer that only gets turned on when I want to do transfers, paper wallet and/or flash drive.  Actually I am thinking multiple.  Like multiple wallets that I transfer through to my main storage.  I know I know, this seems like overkill, but right now, it is the best I can come up with :O
👍  ,
properties (23)
authorthisisit
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t181743504z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:17:42
last_update2017-08-20 18:17:42
depth1
children1
last_payout2017-08-27 18:17:42
cashout_time1969-12-31 23:59:59
total_payout_value0.060 HBD
curator_payout_value0.018 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length580
author_reputation59,209,501,836
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,369,374
net_rshares21,092,274,538
author_curate_reward""
vote details (2)
@ashaman ·
You have just described how cold storage could be achieved in the old days - before hardware wallets existed.

For supported cryptos, a Trezor/Ledger will enable the same level of security as an offline computer used for signing transactions (which you would have to sneaker-net to an online computer in order to broadcast), with the convenience of creating transactions from an online device.
👍  
properties (23)
authorashaman
permlinkre-thisisit-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t184449409z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:44:48
last_update2017-08-20 18:44:48
depth2
children0
last_payout2017-08-27 18:44:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length393
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,371,276
net_rshares446,021,813
author_curate_reward""
vote details (1)
@ugetfunded ·
Interesting article.
properties (22)
authorugetfunded
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t180157100z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 18:02:00
last_update2017-08-20 18:02:00
depth1
children0
last_payout2017-08-27 18:02:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation13,570,875,538,010
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,368,112
net_rshares0
@weirdheadaches ·
$0.02
Great post! Everything is a dictionary length for tech. I love the old days where anyone trying to steal my cash was met with a pistol in face.
👍  
properties (23)
authorweirdheadaches
permlinkre-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t200058866z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 20:01:00
last_update2017-08-20 20:01:00
depth1
children2
last_payout2017-08-27 20:01:00
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.004 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length143
author_reputation10,579,598,073,139
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,376,219
net_rshares6,816,048,551
author_curate_reward""
vote details (1)
@ashaman ·
[People have had BTC stolen the old fashioned way too.](https://www.cnbc.com/2015/06/05/new-york-city-man-robbed-at-gunpoint-for-bitcoin.html)
👍  
properties (23)
authorashaman
permlinkre-weirdheadaches-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t202808124z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"links":["https://www.cnbc.com/2015/06/05/new-york-city-man-robbed-at-gunpoint-for-bitcoin.html"],"app":"steemit/0.1"}
created2017-08-20 20:28:09
last_update2017-08-20 20:28:09
depth2
children1
last_payout2017-08-27 20:28:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length142
author_reputation3,785,245,463,720
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,378,007
net_rshares649,498,667
author_curate_reward""
vote details (1)
@weirdheadaches ·
Geeze!
properties (22)
authorweirdheadaches
permlinkre-ashaman-re-weirdheadaches-re-ashaman-do-you-have-2fa-enabled-do-you-use-a-password-manager-the-convenience-of-cutting-these-corners-is-not-worth-the-risk-20170820t214602883z
categorycryptocurrency
json_metadata{"tags":["cryptocurrency"],"app":"steemit/0.1"}
created2017-08-20 21:46:06
last_update2017-08-20 21:46:06
depth3
children0
last_payout2017-08-27 21:46:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length6
author_reputation10,579,598,073,139
root_title"Do YOU have 2FA enabled? Do you use a password manager? The convenience of cutting these corners is NOT worth the risk!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id12,382,574
net_rshares0