create account

Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE. by louis88

View this thread on: hive.blogpeakd.comecency.com
· @louis88 ·
$24.66
Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE.
Many of you already know what I do on the side. I spend a good amount of my free time doing security analysis and penetration testing on web applications here in our Hive ecosystem. I do this voluntarily, without contracts or a fixed payment, which can sometimes lead to misunderstandings. But that is just how it is.


![image.png](https://files.peakd.com/file/peakd-hive/louis88/23uQJrYteZRY8cAsYTdzbEyoticFgfHpgtqe4mVGWuiifhYCC2k12ytewGD6FzrKS3wk4.png)



This morning, while enjoying my first coffee and scrolling through the Snaps on PeakD, I saw something new. A fresh frontend for skaters on Hive had just been released. Of course, I could not resist and jumped right into checking it for possible security issues. Unfortunately, I did not have to search for long before I came across vulnerabilities. It is something I have seen far too often in Hive projects.

I documented the details of what I found and sent everything directly to the Skatehive team. To their credit, they reacted quickly. They understood the situation immediately and began working on fixing the problems. After their first reply confirming the fix, I checked again and could not find any remaining issues. That is exactly how it should be. When there are security flaws in a public-facing frontend, sometimes every minute counts. A big thank you to the Skatehive team and especially to @xvlad for working so quickly and efficiently to close those issues.

Sadly, it is not always like this. In the past, I have often run into frontend developers who had no idea what I had just found. Many were not even aware of the risks these vulnerabilities carried. What makes it even harder is that I am using my own time, knowledge, and years of experience to help – and yet sometimes I do not even get a thank you. In a few cases, I have even been threatened or completely dismissed. That is frustrating, but as someone wearing the white or grey hat, I have to accept it.

It is a shame we do not have a bug bounty program on Hive. When you find security problems in a project that is doing very well financially, it feels strange not to have any formal recognition. I will not name the project yet, but I can say that there are still several very critical vulnerabilities in that frontend. At least one has a CVSS score of 8.1 (High) and could cause serious trouble if exploited. (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)

No matter how much some people might laugh at or dismiss my work as a security researcher, at the end of the day we are all using a platform that deals with real money. For some, it is not a small amount either. This is why I will not stop doing what I do.

So that was my Sunday. Sitting at my PC with perfect sunshine outside, plenty of coffee, and now finally an evening beer. A day dedicated to keeping Hive a little safer.

Thanks for reading and see you next time.
This show's up, when you try to do bad stuff now ;) GG

![image.png](https://files.peakd.com/file/peakd-hive/louis88/23tRrRstzd4MWR7Gf4bnsZhAtJvRYd61EEEYr1PA2RjkPQpxd1qNhZzPcchZgJ3eX1EFq.png)

![untitled.gif](https://media.tenor.com/nI0Co-Jgy7wAAAAC/jack-sparrow-hat-tip.gif)


#### Do you like what i do? Vote for my Witness and show your Support.

--- 

<div class="pull-left"><div class="text-justify">

[![image.png](https://files.peakd.com/file/peakd-hive/louis88/23v4Zbq5TQyn3aFGQ7YcUyQJQCHhh556WQfTgmeR6EtVe1RWUURNc89oCX25ZFnUHAXww.png)](https://vote.hive.uno/@louis.witness)

##### Vote for my Hive Witness
U can vote for my Witness using Hive Keychain here:  https://vote.hive.uno/@louis.witness

</div></div>
<div class="pull-right"><div class="text-justify">


[![image.png](https://files.peakd.com/file/peakd-hive/louis88/24241zs2F4mEKWwVa9y2CkqHjUcR7Rh2EyRQEXZA5vfHdjEMnq8Ej8R4cWxT1jgAtXQHP.png)](https://primersion.com/he-witnesses)

##### Vote for my Hive Engine Witness

Vote for my Witness on Hive-Engine using Primersion Tool: https://primersion.com/he-witnesses <sup>Enter your Username and search for louis.witness</sup>
</div></div>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 236 others
properties (23)
authorlouis88
permlinkkeeping-hive-and-its-projects-safe-my-sunday-dedicated-to-more-secure-frontends-on-hive
categoryhive-139531
json_metadata{"app":"peakd/2025.8.2","format":"markdown","author":"louis88","tags":["development","security","hive","community","blog","frontend","vulnerabilities","dapps"],"users":["xvlad","louis.witness"],"image":["https://files.peakd.com/file/peakd-hive/louis88/23uQJrYteZRY8cAsYTdzbEyoticFgfHpgtqe4mVGWuiifhYCC2k12ytewGD6FzrKS3wk4.png","https://files.peakd.com/file/peakd-hive/louis88/23tRrRstzd4MWR7Gf4bnsZhAtJvRYd61EEEYr1PA2RjkPQpxd1qNhZzPcchZgJ3eX1EFq.png","https://media.tenor.com/nI0Co-Jgy7wAAAAC/jack-sparrow-hat-tip.gif","https://files.peakd.com/file/peakd-hive/louis88/23v4Zbq5TQyn3aFGQ7YcUyQJQCHhh556WQfTgmeR6EtVe1RWUURNc89oCX25ZFnUHAXww.png","https://files.peakd.com/file/peakd-hive/louis88/24241zs2F4mEKWwVa9y2CkqHjUcR7Rh2EyRQEXZA5vfHdjEMnq8Ej8R4cWxT1jgAtXQHP.png"]}
created2025-08-10 15:59:27
last_update2025-08-10 15:59:27
depth0
children15
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 15:59:27
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value24.658 HBD
promoted0.000 HBD
body_length4,025
author_reputation1,199,199,256,814,378
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,860,796
net_rshares78,123,356,024,663
author_curate_reward""
vote details (300)
@alonicus ·
$0.82
Thank you for what you do !

I like the idea of a bug bounty system, but at the same time I've seen bug bounties  massively abused. The biggest issue is people with no expertise using widely available automated tools to find supposed vulnerabilities. They then email micro-businesses like my own exaggerating the risks and ignoring the fact that other mitigations might be in place (e.g. manual checks), demanding large payouts and saying they'll publicise what they found if the payout isn't received within 24/48/72 hours.

So for Hive, I think we need a bug bounty system designed to reward genuine bug hunters like yourself without opening it up to outsiders who just want to may a quick buck.

That rules out HBD rewards paid from the DHF, and even HP rewards could be put into the power down process as soon as received. So perhaps some kind of delegation pools could be set up; that way, it's the use of the delegation in curation over a period of time which generates the rewards. I know that's not a perfect solution, but it's the only one I can think of so far that keeps capital in the system while rewarding internal bug hunters !
👍  , , , , , ,
properties (23)
authoralonicus
permlinkre-louis88-t0sgsx
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 17:34:09
last_update2025-08-10 17:34:09
depth1
children1
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 17:34:09
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.816 HBD
promoted0.000 HBD
body_length1,142
author_reputation156,077,115,036,780
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,863,912
net_rshares2,616,244,421,715
author_curate_reward""
vote details (7)
@topcomment ·
<center>
**Your reply is upvoted by [@topcomment](/@topcomment); a manual curation service that rewards meaningful and engaging comments.**
<center>
**[More Info](/@topcomment/topcomment-curation-service-info) - [Support us!](/hive/@topcomment/support-topcomment-a-delegation-and-earn-80percent-curation-rewards) - [Reports](/created/topcommentreport) - [Discord Channel](https://discord.gg/u7ebA2QKCd)**
</center>
[![image.png](https://files.peakd.com/file/peakd-hive/topcomment/EpGRgMJ92JzvktbWphJhBiKrsNYoqLrXvTGH5yP9offkMeLLFZ7PrCbT1T4SfMDC5NS.png)](https://peakd.com/@topcomment)<hr><center><b>Curated by <a href="/@friendlymoose">friendlymoose</a></b></center>
properties (22)
authortopcomment
permlinkre-alonicus-1754854969
categoryhive-139531
json_metadata"{"tags": ["hive-139531"], "app": "HiveDiscoMod"}"
created2025-08-10 19:42:48
last_update2025-08-10 19:42:48
depth2
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 19:42:48
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length666
author_reputation8,498,317,260,750
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,866,203
net_rshares0
@beerlover ·
<div class='pull-right'>https://files.peakd.com/file/peakd-hive/beerlover/yiuU6bdf-beerlover20gives20BEER.gif<p><sup><a href='https://hive-engine.com/?p=market&t=BEER'>View or trade </a> <code>BEER</code>.</sup></p></div><center><br> <p>Hey @louis88, here is a little bit of <code>BEER</code> from @steevc for you. Enjoy it!</p> <p>We love your support by voting @detlev.witness on <a href='https://vote.hive.uno/@detlev.witness'>HIVE</a> </a>.</p> </center><div></div>
properties (22)
authorbeerlover
permlinkre-louis88-keeping-hive-and-its-projects-safe-my-sunday-dedicated-to-more-secure-frontends-on-hive-20250810t164904614z
categoryhive-139531
json_metadata{"app":"beerlover/3.0","language":"rust","developer":"wehmoen"}
created2025-08-10 16:49:03
last_update2025-08-10 16:49:03
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 16:49:03
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length470
author_reputation25,840,105,692,251
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,862,486
net_rshares0
@beerlover ·
<div class='pull-right'>https://files.peakd.com/file/peakd-hive/beerlover/yiuU6bdf-beerlover20gives20BEER.gif<p><sup><a href='https://hive-engine.com/?p=market&t=BEER'>View or trade </a> <code>BEER</code>.</sup></p></div><center><br> <p>Hey @louis88, here is a little bit of <code>BEER</code> from @steevc for you. Enjoy it!</p> <p>Did you know that <a href='https://dcity.io/city</b>you can use <b>BEER</b> at dCity game</a> to buy cards to rule the world.</p> </center><div></div>
properties (22)
authorbeerlover
permlinkre-louis88-keeping-hive-and-its-projects-safe-my-sunday-dedicated-to-more-secure-frontends-on-hive-20250810t164910836z
categoryhive-139531
json_metadata{"app":"beerlover/3.0","language":"rust","developer":"wehmoen"}
created2025-08-10 16:49:09
last_update2025-08-10 16:49:09
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 16:49:09
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length483
author_reputation25,840,105,692,251
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,862,490
net_rshares0
@bozz ·
$0.04
I appreciate what you do trying to make HIVE a safer place for everyone.  I don't understand it all either, but if someone brought it up to me I would work to get it fixed or find someone who could.
👍  ,
properties (23)
authorbozz
permlinkre-louis88-t0sgjc
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 17:28:24
last_update2025-08-10 17:28:24
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 17:28:24
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.036 HBD
promoted0.000 HBD
body_length198
author_reputation2,312,526,916,246,487
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,863,720
net_rshares117,526,016,118
author_curate_reward""
vote details (2)
@friendlymoose ·
As with many things on Hive; people really appreciate what you do, but most of the people don't want (or cannot) reward you for it.

It is with posts like this that you can create awareness and rewards for the things you have done. 
properties (22)
authorfriendlymoose
permlinkre-louis88-t0smug
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 19:44:42
last_update2025-08-10 19:44:42
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 19:44:42
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length232
author_reputation426,245,736,870,460
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,866,237
net_rshares0
@memess ·
Hey, what do you test / look for ? 
There is a new hive front end being made (hivesnaps app) and i was wondering if it was safe but sadly i dont have the required skills to test it
properties (22)
authormemess
permlinkre-louis88-2025810t185456337z
categoryhive-139531
json_metadata{"links":[],"type":"comment","tags":["hive-139531","development","security","hive","community","blog","frontend","vulnerabilities","dapps"],"app":"ecency/3.3.3-mobile","format":"markdown+html"}
created2025-08-10 16:54:57
last_update2025-08-10 16:54:57
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 16:54:57
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length180
author_reputation25,016,735,258,963
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,862,666
net_rshares0
@mengao ·
$0.16
Thank you for your help!!
👍  , ,
properties (23)
authormengao
permlinkre-louis88-t0scrl
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 16:06:57
last_update2025-08-10 16:06:57
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 16:06:57
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.161 HBD
promoted0.000 HBD
body_length25
author_reputation115,908,412,987,509
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,861,111
net_rshares520,769,667,938
author_curate_reward""
vote details (3)
@steevc ·
$0.30
Any public facing service is vulnerable and likely to be attacked these days. Thanks for caring. The Skatehive project looks really cool. 

Are checks done generally on what goes into Hive posts? I assume it's possible to include malicious links, but would those get filtered out somewhere or do the front ends need to block specific posts or accounts? 

!BEER
👍  , ,
properties (23)
authorsteevc
permlinkre-louis88-t0sep8
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 16:48:45
last_update2025-08-10 16:48:45
depth1
children1
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 16:48:45
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.300 HBD
promoted0.000 HBD
body_length360
author_reputation1,399,169,854,518,450
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,862,480
net_rshares967,123,326,784
author_curate_reward""
vote details (3)
@louis88 ·
$0.61
Yea, it's not easier in Vibe-Coding-Times and new Services popping up daily. Ur welcome sir. Skatehive looks dope, yea. Most-Likely Content in Posts are my first focus, cause it's the most obvious one. We have also a Service running on a Discord Server that checks every single Post/Comment on HIVE for Links etc. and notifies us/ the Moderators/Admins to see whats going on and be alerted very early. It's then up to the Frontends hide/mute etc. stuff but mostly not done on new services ^.^.
👍  , ,
properties (23)
authorlouis88
permlinkre-steevc-t0sfsm
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2"}
created2025-08-10 17:12:24
last_update2025-08-10 17:12:24
depth2
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 17:12:24
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.611 HBD
promoted0.000 HBD
body_length493
author_reputation1,199,199,256,814,378
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,863,209
net_rshares1,958,428,562,805
author_curate_reward""
vote details (3)
@vaipraonde ·
Thanks for your help. 
Great job!
properties (22)
authorvaipraonde
permlinkre-louis88-t0sgnt
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 17:31:06
last_update2025-08-10 17:31:06
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 17:31:06
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length33
author_reputation82,396,244,761,399
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,863,805
net_rshares0
@vaipraonde ·
Want another mission?! 🤔
properties (22)
authorvaipraonde
permlinkre-louis88-t0sl3w
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 19:07:09
last_update2025-08-10 19:07:09
depth1
children2
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 19:07:09
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length24
author_reputation82,396,244,761,399
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,865,668
net_rshares0
@louis88 ·
$0.42
Sure, why not - if it fits my skillZ
👍  ,
properties (23)
authorlouis88
permlinkre-vaipraonde-t0sl5k
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2"}
created2025-08-10 19:08:09
last_update2025-08-10 19:08:09
depth2
children1
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 19:08:09
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.420 HBD
promoted0.000 HBD
body_length36
author_reputation1,199,199,256,814,378
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,865,689
net_rshares1,347,278,541,559
author_curate_reward""
vote details (2)
@vaipraonde ·
How can I find you on discord?!
properties (22)
authorvaipraonde
permlinkre-louis88-t0smdy
categoryhive-139531
json_metadata{"tags":["hive-139531"],"app":"peakd/2025.8.2","image":[],"users":[]}
created2025-08-10 19:34:48
last_update2025-08-10 19:34:48
depth3
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 19:34:48
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length31
author_reputation82,396,244,761,399
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,866,076
net_rshares0
@web-gnar ·
awesome dude thank you for donating your time to help the skatehive strengthen its infrastructure! we owe ya one!
properties (22)
authorweb-gnar
permlink20250810t174314692z
categoryhive-139531
json_metadata"{"app":"Skatehive App 3.0","tags":[],"images":[]}"
created2025-08-10 17:43:15
last_update2025-08-10 17:43:15
depth1
children0
last_payout1969-12-31 23:59:59
cashout_time2025-08-17 17:43:15
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length113
author_reputation169,484,749,686,910
root_title"Keeping HIVE and it's Projects safe - My Sunday dedicated to more secure Frontends on HIVE."
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id144,864,074
net_rshares0