create account

Steemit User's Biggest Security Flaw On Comments by ebonsi

View this thread on: hive.blogpeakd.comecency.com
· @ebonsi · (edited)
$0.07
Steemit User's Biggest Security Flaw On Comments
<html>
<h3><em><strong>I was asked by a friend (Francisco Sand) to write on this issue. We are both new on Steemit but by using the network, we already spot a user failure on the software interface.</strong></em></h3>
<p>https://i.imgsafe.org/eae05f0078.png</p>
<p>If Steemit is serious about the good functioning of the community and aspires to attract serious and sane debates to the conversation, the developers need to fix this security flaw. Besides, after resolving this issue, will take the weight off - of the people that manage the user's posting on the network.</p>
<p>The security flaw is the same flaw found on networks like "<strong>Nextdoor</strong>", <strong>Twitter</strong> and many others I spotted on the internet.</p>
<p>The security flaw has to do with the user's comment on the post. At this point, many networks need to learn a lesson from Facebook. The lesson on user's security is that the person that "Submit a Story" must have all the permissions and rights to their post. That means, if a person post something on Steemit and a jerk or a troll comes along and make a stupid comment on the post, the owner of the post have the right and decide if he/she will leave the comment or delete the offending comment. That is the best way to resolve the incidents of "trolls/jerks" and their non sense comments.&nbsp;</p>
<p>The "flag" feature still can be used for serious threats or things that require a more strong intervention from the community.</p>
<p><em><strong>Should I repeat this? Ok, one more time;</strong></em></p>
<p>The person that post or "submit a story" must have total control of his post. He/She must have control of:</p>
<p>1. Editing the post &nbsp;&nbsp;&lt;-- Already there</p>
<h2>2. Deleting comments &lt;-- <strong>Needs to be implemented urgent!</strong></h2>
<p>3. Sharing the post &nbsp;&lt;-- Already there</p>
<p>4. Deleting the entire post &lt;-- Already there</p>
<p><em>I hope this post will be clear enough to start this process. I will also suggest this on Github;</em></p>
<p><em>https://github.com&nbsp;</em></p>
<p><em><strong>Foot Credit:</strong></em></p>
<p><em>Sketch of how this image illustration was created?</em></p>
<p><em>https://i.imgsafe.org/eba225535e.png</em></p>
<p><em>Who is hosting our images?</em></p>
<p><em>Image Safe</em></p>
<p><em>https://i.imgsafe.org/</em></p>
<p><em>Who helped with free images and ideas;</em></p>
<p><em>PixaBay</em></p>
<p><em>https://pixabay.com</em></p>
</html>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 15 others
properties (23)
authorebonsi
permlinksteemit-user-s-biggest-security-flaw-on-comments
categorytechnology
json_metadata{"tags":["technology","abuse","steemit","news","art"],"image":["https://i.imgsafe.org/eae05f0078.png","https://i.imgsafe.org/eba225535e.png"],"links":["https://github.com","https://i.imgsafe.org/","https://pixabay.com"],"app":"steemit/0.1","format":"html"}
created2016-11-07 00:59:54
last_update2016-11-07 01:03:54
depth0
children28
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.056 HBD
curator_payout_value0.015 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,470
author_reputation201,927,984,970
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,703,103
net_rshares2,067,893,464,653
author_curate_reward""
vote details (79)
@cyrano ·
I don't see how that's a security flaw.

Steemit is about freedom of expression, IMO. That includes comments on other people's posts. While the ability to "delete" posts (note that you cannot really delete anything from the blockchain anyway)  might seem desirable as a means to handle the troll problem, if it exists, this is essentially a means for censorship.

The best defense against a troll is to ignore it. If you try to silence it it will only come back with a vengeance.
The best defense against a stupid comment is a better argument.

Censorship is unnecessary and counterproductive.
👍  ,
properties (23)
authorcyrano
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t075313844z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 07:53:12
last_update2016-11-07 07:53:12
depth1
children4
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length593
author_reputation2,476,469,639,719
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,704,677
net_rshares395,318,257,656
author_curate_reward""
vote details (2)
@ebonsi ·
I don't see how that could be a censorship! Censorship is deleting a story that someone posts here! Censorship is to delete or block someone's account, censorship is to stop a person from expressing themselves through a story. You are elevating people's comments to a degree of extreme importance. Even more important than the story. The true fact is who post or write a story becomes the moderator of the story. It is only right! After all, it is his/her story. If you think the story is a fraud, a plagiarism, go ahead and flag the story!
properties (22)
authorebonsi
permlinkre-cyrano-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t184416257z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 18:45:18
last_update2016-11-07 18:45:18
depth2
children3
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length540
author_reputation201,927,984,970
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,707,860
net_rshares0
@walden ·
Eduardo, no tenes ni la mas minima idea de lo que hablas.
A comment has the same intrinsic freedom of expression than a post.
properties (22)
authorwalden
permlinkre-ebonsi-re-cyrano-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t200337694z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 20:03:39
last_update2016-11-07 20:03:39
depth3
children2
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length125
author_reputation30,946,920,431,850
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,708,338
net_rshares0
@gduran ·
$0.03
Wouldn't that just give me the chance to delete any opinions contrary to mine?
👍  ,
properties (23)
authorgduran
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t015131262z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 01:51:30
last_update2016-11-07 01:51:30
depth1
children5
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.021 HBD
curator_payout_value0.006 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length78
author_reputation58,593,071,644,427
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,703,280
net_rshares850,455,798,285
author_curate_reward""
vote details (2)
@ebonsi ·
That is a decision for the post owner to take! I never deleted comments contrary to mine but I have deleted comments from "jerks", "spoofers" and "trolls."
👍  
properties (23)
authorebonsi
permlinkre-gduran-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t015829713z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 01:59:27
last_update2016-11-07 01:59:27
depth2
children4
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length155
author_reputation201,927,984,970
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,703,308
net_rshares28,414,387,257
author_curate_reward""
vote details (1)
@dantheman ·
Except that abusers could delete comments that bring valid info to the fraud.
👍  , , , , , , ,
properties (23)
authordantheman
permlinkre-ebonsi-re-gduran-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t034548396z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 03:45:48
last_update2016-11-07 03:45:48
depth3
children3
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length77
author_reputation240,292,002,602,347
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,703,722
net_rshares24,441,896,246
author_curate_reward""
vote details (8)
@linkback-bot-v0 ·
This post has been linked to from another place on Steem.


  - [Advanced Steem Metrics Report for 7th November 2016](https://steemit.com/steemit/@ontofractal/advanced-steem-metrics-report-for-7th-november-2016) by @ontofractal




Learn more about and upvote to support [**linkback bot v0.5**](https://steemit.com/steemit/@ontofractal/steem-linkback-bot-v0-5-the-reddit-awareness-release). Flag this comment if you don't want the bot to continue posting linkbacks for your posts.

Built by @ontofractal
👍  
properties (23)
authorlinkback-bot-v0
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-linkbacks
categorytechnology
json_metadata{}
created2016-11-08 19:17:30
last_update2016-11-08 19:17:30
depth1
children0
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length504
author_reputation1,915,954,976,722
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,724,194
net_rshares124,377,773
author_curate_reward""
vote details (1)
@onthewayout ·
I am not sure if you have noticed but you seldom see trolls around steemit. The reason being that once they are identified they usually get downvoted/flagged to oblivion by the community and their posts or comments become less visible.

You also need to consider that all posts and comments are recorded in the blockchain (which no one owns). Once there, nothing can be deleted. It might not be visible in the website but you can see them using other tools or interfaces.

So once a piece of data is recorded in the blockchain it becomes inmutable and is recorded for posterity (unless if you are referring to Ethereum ;)
👍  
properties (23)
authoronthewayout
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t051207324z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 05:12:06
last_update2016-11-07 05:12:06
depth1
children3
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length621
author_reputation13,205,527,560,619
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,704,165
net_rshares124,377,773
author_curate_reward""
vote details (1)
@ebonsi · (edited)
Your observation that there are not trolls on steemit is not valid. Is my actions step by step will be in the logs, sure! Each action has been recorded. But that is not what is in question here! Suppose I create a story or submit a story. Then, a troll come along and makes a nonsense comment spoofing the story. I can just delete the entire story and post again. Not very practicable but effective. However, trolls do not give up that easy! They have nothing to do and they like to hang around obstructing the post! People do not feel very motivated to comment or participate in a post that has been trolled. Have the ability to remove the troll is a right that must be given to the post owner.
properties (22)
authorebonsi
permlinkre-onthewayout-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t061412209z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 06:15:12
last_update2016-11-07 07:47:18
depth2
children2
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length695
author_reputation201,927,984,970
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,704,359
net_rshares0
@onthewayout · (edited)
I never said that there aren't any trolls in Steemit.  I said that you seldom find trolls which is not the same. What you are asking for cannot be done on a blockchain as there is no central point of control (that's what makes it censor resistent). If you could do that then it would not be a blockchain it would just a be centralized database.
properties (22)
authoronthewayout
permlinkre-ebonsi-re-onthewayout-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161108t045434662z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-08 04:54:39
last_update2016-11-08 04:55:06
depth3
children1
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length344
author_reputation13,205,527,560,619
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,716,979
net_rshares0
@pfunk ·
Thanks for your concern but I don't see this happening and wouldn't want to see it happening. Feel free to stay on Facebook.
👍  ,
properties (23)
authorpfunk
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t170006911z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 17:00:09
last_update2016-11-07 17:00:09
depth1
children10
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length124
author_reputation221,632,045,904,452
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,707,266
net_rshares337,902,508,231
author_curate_reward""
vote details (2)
@ebonsi ·
Like I said in the other comment, That is why you have the flag feature! I am beginning to think here that the intentions are others ones besides this type of fraud. Example, I wouldn't delete your comment, even thou is irrelevant, meaning that is worth "zero" because it does not put an "iota" to the discussion. It only shows your imperial wishes!
properties (22)
authorebonsi
permlinkre-pfunk-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t181130731z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 18:12:30
last_update2016-11-07 18:12:30
depth2
children9
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length349
author_reputation201,927,984,970
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,707,692
net_rshares0
@pfunk · (edited)
k. You've been here for a week. Check it out a bit more.
properties (22)
authorpfunk
permlinkre-ebonsi-re-pfunk-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161108t032556964z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-08 03:25:57
last_update2016-11-08 03:27:18
depth3
children5
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length56
author_reputation221,632,045,904,452
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,715,344
net_rshares0
@walden ·
Yes, by all means, if you like Facebook more, please stay there....
properties (22)
authorwalden
permlinkre-ebonsi-re-pfunk-re-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t185517954z
categorytechnology
json_metadata{"tags":["technology"]}
created2016-11-07 18:55:18
last_update2016-11-07 18:55:18
depth3
children2
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length67
author_reputation30,946,920,431,850
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,707,915
net_rshares0
@samupaha · (edited)
It's a feature, not a security flaw. Blockchain based platform is censorship resistant so you can't delete anything that other users have written.

In the future there will be other user interfaces to the blockchain (besides Steemit). Probably some of those will have a feature that gives rights to users to hide comments that they don't like.

Edit: Actually there is one way how this can be implemented without breaking anything or taking away essential features from the blockchain: https://steemit.com/steem-ideas/@samupaha/feature-proposal-ownable-tags
properties (22)
authorsamupaha
permlinkre-ebonsi-steemit-user-s-biggest-security-flaw-on-comments-20161107t080648621z
categorytechnology
json_metadata{"tags":["technology"],"links":["https://steemit.com/steem-ideas/@samupaha/feature-proposal-ownable-tags"]}
created2016-11-07 08:06:48
last_update2016-11-07 11:11:30
depth1
children0
last_payout2016-12-08 04:38:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length557
author_reputation43,637,433,899,367
root_title"Steemit User's Biggest Security Flaw On Comments"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,704,709
net_rshares0