create account

Offline Attack on Steem User Credentials by robinhood

View this thread on: hive.blogpeakd.comecency.com
· @robinhood ·
$7,754.81
Offline Attack on Steem User Credentials
Moments ago I changed the owner/active/posting/memo keys of ~500 Steem accounts.  

I changed their keys to Steemit's key so Steemit can allow these users to regain access via the recovery mechanism they established.  

I was able to do this because I was able to guess these account's passwords.  

I was able to guess their passwords because of what I would argue is a flaw in Steem's UI.  Specifically, it currently allows users-chosen passwords by default.  In most applications user-chosen password are not problematic.  However, they are problematic in this use-case because a scrambled form of each user's password must be stored on Steem's public blockchain meaning anyone with a copy of the blockchain can mount a large-scale offline dictionary attack to recover them.  Research as well as real-world precedent has repeatedly shown that a non-trivial fraction of users are incapable of choosing passwords resistent to offline-attack even when password complexity requirements are enforced.  

Forcing machine-generated passwords in the UI for owner/active keys would be one possible step towards mitigation.  I'm aware of the usability counter-argument to this suggestion.  However, consider that my effort expended ~1 USD of computing resources and ended up recovering the credentials of accounts with liquid assets valued in the thousands and semi-liquid assets (SP) in the tens of thousands.  Given this fact, it would be hopelessly naive to assume offline attacks will not be attempted in the future at much greater scale and by totally bad actors.

I invite others with constructive mitigation ideas to share them.

One futher point, unless explicitly invited by Steemit, I will not attempt any future white hat shenanigans.  My motivation was to alert this community to a genuine danger and do so in manner that hopefully leaves a more lasting impression than yet another "how to pick a strong password" snorefest post.

[![12345](http://media-cache-ec0.pinimg.com/736x/ff/96/13/ff96133faab0e386e5c27819638a2172.jpg)](https://www.youtube.com/watch?v=a6iW-8xPw3k)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 358 others
👎  
properties (23)
authorrobinhood
permlinkoffline-attack-on-steem-user-credentials
categorysteem
json_metadata{"tags":["steem","steemit","security","passwords"],"links":["http://media-cache-ec0.pinimg.com/736x/ff/96/13/ff96133faab0e386e5c27819638a2172.jpg)](https://www.youtube.com/watch?v=a6iW-8xPw3k"]}
created2016-07-19 05:56:00
last_update2016-07-19 05:56:00
depth0
children71
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value5,818.194 HBD
curator_payout_value1,936.618 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,077
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id181,564
net_rshares130,226,634,576,617
author_curate_reward""
vote details (423)
@aaseb ·
wow! so basically you hacked 500 accounts and gave the keys back to steemit!?
well good job!
👍  
properties (23)
authoraaseb
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t223719968z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 22:37:24
last_update2016-07-19 22:37:24
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length92
author_reputation470,722,236,683
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id201,639
net_rshares5,253,185,686
author_curate_reward""
vote details (1)
@arhag ·
$672.94
Yup, this is exactly what I have been shouting about for weeks now and expected would eventually happen. I am happy that you are a white hat and didn't take control of the accounts for yourself to profit from.

I believe it is better to push away new users with less user friendly registration (that forces them to use a randomly generated key that they must store securely and use password managers to manage) than to bring them aboard easily only to completely piss them off when their account or funds are stolen [1]. It is our job to make it as user-friendly as possible and to provide great resources educating users how to generate and manage random high-entropy passwords. But I don't agree with compromising their security because it is "too hard" and we don't want to lose them as new users.

[1] Although the new recovery feature allows them to get their account back. Most funds are usually locked in the time-locked Steem Power, so hopefully not too much financial damage would be done by the time they recover their account. And there are plans for a user opt-in and configurable time-locked savings account to even protect their more liquid STEEM and Steem Dollar funds from being stolen by hackers assuming they recover their account in a few days.
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorarhag
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t104218144z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 10:42:18
last_update2016-07-19 10:42:18
depth1
children14
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value504.762 HBD
curator_payout_value168.181 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,263
author_reputation52,490,827,205,383
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id185,235
net_rshares36,990,417,460,332
author_curate_reward""
vote details (45)
@cass ·
$176.60
… we are in needs of a bug bounty program with high rewards, that people are happy to publish the flaws, instead of misusing them for the own profit in the short run! **Thank you for being honest and alarming the devs and community - and not run with the money** …! 

# Chapeau !
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorcass
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160719t225759748z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 22:58:00
last_update2016-07-19 22:58:00
depth2
children6
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value132.492 HBD
curator_payout_value44.103 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length279
author_reputation87,554,098,144,619
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id202,134
net_rshares18,064,825,530,140
author_curate_reward""
vote details (29)
@cass ·
$125.78
and tipping is always an option as well -  *thx again*!
👍  , , , , , , , , , , ,
properties (23)
authorcass
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t004555546z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:45:57
last_update2016-07-20 00:45:57
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value94.350 HBD
curator_payout_value31.426 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length55
author_reputation87,554,098,144,619
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,672
net_rshares14,952,715,546,515
author_curate_reward""
vote details (12)
@cass · (edited)
$124.50
I WILL donate/contribute my rewards gotten out of my comments here @robinhood as well, and **you guys here**  should considering to do this as well...if everybody here WILL doing this i'd double the **comment** payment amount to donate out of my pockets again!
👍  , , , , , , , , , , ,
properties (23)
authorcass
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t124910967z
categorysteem
json_metadata{"tags":["steem"],"users":["robinhood"]}
created2016-07-20 12:49:09
last_update2016-07-20 15:55:42
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value96.396 HBD
curator_payout_value28.100 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length260
author_reputation87,554,098,144,619
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id218,282
net_rshares14,867,402,568,490
author_curate_reward""
vote details (12)
@hastla ·
$24.90
@cass - the largest flaw now in my opinion is that overgrowing "tag-spamming" people do. When you have for example in top 12 of "marijuana" topic just 3 related ones the platform has a massive problem.  This get worse hour by our and people tag nearly all their posts wrong.
👍  , , , ,
properties (23)
authorhastla
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t194323327z
categorysteem
json_metadata{"tags":["steem"],"users":["cass"]}
created2016-07-20 19:43:27
last_update2016-07-20 19:43:27
depth3
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value18.682 HBD
curator_payout_value6.221 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length274
author_reputation3,558,745,414,140
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id227,590
net_rshares5,753,803,506,316
author_curate_reward""
vote details (5)
@itsjoeco ·
Happy to introduce anyone to Jacob at Cobalt - best bug bounties with a specialization in cryptocurrency companies.
properties (22)
authoritsjoeco
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t191400093z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 19:13:57
last_update2016-07-20 19:13:57
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length115
author_reputation3,299,547,481,773
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id226,791
net_rshares0
@willytrader ·
first official STEEM LOTTERY  https://steemit.com/lottery/@willytrader/first-official-steem-lottery
properties (22)
authorwillytrader
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160721t014800864z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/lottery/@willytrader/first-official-steem-lottery"]}
created2016-07-21 01:49:21
last_update2016-07-21 01:49:21
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length99
author_reputation-445,425,524,475
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id235,558
net_rshares0
@henchman ·
https://i.imgflip.com/17n89a.jpg
👍  
properties (23)
authorhenchman
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t102505197z
categorysteem
json_metadata{"tags":["steem"],"image":["https://i.imgflip.com/17n89a.jpg"]}
created2016-07-20 10:25:00
last_update2016-07-20 10:25:00
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length32
author_reputation3,059,573,385
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id215,563
net_rshares112,645,773
author_curate_reward""
vote details (1)
@ma3 ·
$0.04
This is someting i'm really concerned about arhag, do you have any information i can use at the moment to protect myself further?
👍  
properties (23)
authorma3
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160719t234313059z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 23:43:09
last_update2016-07-19 23:43:09
depth2
children3
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.007 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length129
author_reputation1,455,496,260,273
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id203,191
net_rshares20,470,926,872
author_curate_reward""
vote details (1)
@arhag ·
$0.65
I do actually. I just wrote [this post](https://steemit.com/steem/@arhag/can-you-remember-your-steemit-password-if-so-you-are-in-danger) about the importance of using password managers.
👍  , , ,
properties (23)
authorarhag
permlinkre-ma3-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t005151515z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/steem/@arhag/can-you-remember-your-steemit-password-if-so-you-are-in-danger"]}
created2016-07-20 00:51:51
last_update2016-07-20 00:51:51
depth3
children2
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.494 HBD
curator_payout_value0.160 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length185
author_reputation52,490,827,205,383
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,793
net_rshares356,686,422,342
author_curate_reward""
vote details (4)
@mranderson ·
Amazing work and really making a difference in how we all move forward in the world.
👍  
properties (23)
authormranderson
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t223846247z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 22:38:45
last_update2016-07-20 22:38:45
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length84
author_reputation4,004,740,218,138
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id231,956
net_rshares2,345,159,469
author_curate_reward""
vote details (1)
@steemitpolitics · (edited)
hi @arhag, please check my latest post out. I wrote it to you and the other whales. Maybe you will agree with it :)
https://steemit.com/steemit/@steemitpolitics/6rqxnc-to-the-whales-get-your-head-out-of-your-ass-and-vote-good-content-up-you-are-harming-steemit
👍  
properties (23)
authorsteemitpolitics
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t192711624z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/steemit/@steemitpolitics/6rqxnc-to-the-whales-get-your-head-out-of-your-ass-and-vote-good-content-up-you-are-harming-steemit"],"users":["arhag"]}
created2016-07-20 19:27:15
last_update2016-07-20 19:38:36
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length260
author_reputation2,439,451,239,199
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id227,145
net_rshares1,403,787,926
author_curate_reward""
vote details (1)
@belfordz ·
Its a cool concept, but I'm sorry, I call BS. 

I have looked at the code that handles hashing, salting and encrypting passwords before they are placed into the block chain and I can say with 99.5% certainty that you did not accomplish the hack you claim to have.

In theory it is possible, but the computational complexity of uncovering even 1 of the passwords from the blockchain would be more difficult that mining the largest amount held by any user on the block chain.

Sorry to hurt your feelings and call you out, but if you are to fool this community you are going to need to prove that you a. have the knowledge required to mount such a large scale offline attack, and b. you would have mentioned the actual difficulty of doing so.
properties (22)
authorbelfordz
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002303037z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:22:57
last_update2016-07-20 00:22:57
depth1
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length740
author_reputation34,078,890,529
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,122
net_rshares0
@lukestokes ·
$97.91
> anyone with a copy of the blockchain can mount a large-scale offline dictionary attack to recover them. Research as well as real-world precedent has repeatedly shown that a non-trivial fraction of users are incapable of choosing passwords resistent to offline-attack even when password complexity requirements are enforced

They didn't claim to crack any hashing algorithm. A dictionary attack simply goes through a dictionary of possible passwords and tries each one until it finds a matching hash. Might want to reconsider that 0.5% chance.
👍  , , ,
properties (23)
authorlukestokes
permlinkre-belfordz-re-robinhood-offline-attack-on-steem-user-credentials-20160720t003630552z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:36:30
last_update2016-07-20 00:36:30
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value73.434 HBD
curator_payout_value24.471 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length544
author_reputation555,781,629,106,002
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,437
net_rshares12,986,583,202,202
author_curate_reward""
vote details (4)
@bergy ·
Thanks, I guess?
properties (22)
authorbergy
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t003904626z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:39:06
last_update2016-07-20 00:39:06
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length16
author_reputation4,708,999,218,237
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,508
net_rshares0
@blakemiles84 ·
$0.52
Hm. I vote that you continue to do this and make posts about how you did it, and what recommendations you made. 

I promise I will upvote you every time I see it :P 

You're the first white hat I've seeing doing these sorts of white hat things in crypto since I got in the game a year ago!
👍  
properties (23)
authorblakemiles84
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t220711091z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 22:07:12
last_update2016-07-20 22:07:12
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.516 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length289
author_reputation51,861,865,663,185
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id231,081
net_rshares273,929,931,739
author_curate_reward""
vote details (1)
@bleepcoin ·
i changed it now
properties (22)
authorbleepcoin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t035804636z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 03:58:03
last_update2016-07-20 03:58:03
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length16
author_reputation30,703,823,306,707
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id208,680
net_rshares0
@conda ·
Up vote for space balls photo
properties (22)
authorconda
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t192254564z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 19:22:54
last_update2016-07-20 19:22:54
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length29
author_reputation222,031,173,748
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id227,038
net_rshares0
@cryptogee ·
$0.08
Very interesting, so is this just a problem with user-generated passwords?

Thanks
*CG*
👍  ,
properties (23)
authorcryptogee
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t001003519z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:10:06
last_update2016-07-20 00:10:06
depth1
children3
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.076 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length87
author_reputation419,387,439,147,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id203,842
net_rshares67,102,256,013
author_curate_reward""
vote details (2)
@robinhood ·
$0.68
I dug into the code for the "suggest password" option Steem provides at signup and as far as I could tell the logic there was 100% kosher.
👍  
properties (23)
authorrobinhood
permlinkre-cryptogee-re-robinhood-offline-attack-on-steem-user-credentials-20160720t001847000z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:18:48
last_update2016-07-20 00:18:48
depth2
children2
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.510 HBD
curator_payout_value0.167 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length138
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,033
net_rshares352,268,673,794
author_curate_reward""
vote details (1)
@liondani ·
what does that mean? Was it good?
properties (22)
authorliondani
permlinkre-robinhood-re-cryptogee-re-robinhood-offline-attack-on-steem-user-credentials-20160720t012502032z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 01:25:03
last_update2016-07-20 01:25:03
depth3
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length33
author_reputation95,095,146,236,111
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,501
net_rshares0
@cyberdesire ·
The SpaceBalls is the my favorite movie :)
👍  
properties (23)
authorcyberdesire
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t192002342z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 19:20:06
last_update2016-07-20 19:20:06
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length42
author_reputation470,637,554,050
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id226,968
net_rshares111,900,634
author_curate_reward""
vote details (1)
@domavila ·
$0.15
This is why I proposed 2FA. I understand 2FA is hard to implement on the blockchain but as the saying goes "when there is a will there is a way". I feel very unsafe on this platform without 2FA. Please read this https://steemit.com/steemit/@domavila/two-factor-authentication-and-why-we-need-it-now
👍  , , , , ,
properties (23)
authordomavila
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t114515951z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/steemit/@domavila/two-factor-authentication-and-why-we-need-it-now"]}
created2016-07-19 11:45:15
last_update2016-07-19 11:45:15
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.116 HBD
curator_payout_value0.029 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length298
author_reputation3,816,570,043,566
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id186,210
net_rshares81,457,334,073
author_curate_reward""
vote details (6)
@dony91 ·
Amazing work and really making a difference in how we all move forward in the world.
properties (22)
authordony91
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t051123372z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-21 05:11:24
last_update2016-07-21 05:11:24
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length84
author_reputation3,380,253,503
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id238,889
net_rshares0
@endgame ·
Nice video lol thanks!
properties (22)
authorendgame
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t111625716z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 11:16:27
last_update2016-07-20 11:16:27
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length22
author_reputation-1,051,794,900,426
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id216,529
net_rshares0
@eric-boucher ·
Thanks a lot for the words of advice. Namaste   :)
properties (22)
authoreric-boucher
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t184937006z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 18:49:36
last_update2016-07-20 18:49:36
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length50
author_reputation68,503,601,066,539
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id226,165
net_rshares0
@faddat ·
Anyone have a recommended method of machine-generating a password?
properties (22)
authorfaddat
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t173131296z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 17:31:30
last_update2016-07-20 17:31:30
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length66
author_reputation36,581,868,473,026
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id224,220
net_rshares0
@fyrstikken ·
$0.43
Thank for a great whitehat hack @robinhood 

People need to READ THIS AND TAKE SECURITY SERIOUSLY!!!! 

https://steemit.com/steemit/@fyrstikken/steemit-security-exchanges-and-why-by-a-guy-that-has-been-in-crypto-since-2009-new-people-read-this-now
👍  , ,
properties (23)
authorfyrstikken
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t053106955z
categorysteem
json_metadata{"tags":["steem"],"users":["robinhood"],"links":["https://steemit.com/steemit/@fyrstikken/steemit-security-exchanges-and-why-by-a-guy-that-has-been-in-crypto-since-2009-new-people-read-this-now"]}
created2016-07-20 05:31:06
last_update2016-07-20 05:31:06
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.400 HBD
curator_payout_value0.029 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length247
author_reputation377,187,606,449,589
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id210,303
net_rshares229,395,502,593
author_curate_reward""
vote details (3)
@geronimo ·
@robinhood : you are just awesome. I cannot think about how much the steem community and especially the developers need to thank you. You are incredible. Thanks for that.
properties (22)
authorgeronimo
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t151022753z
categorysteem
json_metadata{"tags":["steem"],"users":["robinhood"]}
created2016-07-20 15:10:24
last_update2016-07-20 15:10:24
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length170
author_reputation2,923,721,121,912
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id221,323
net_rshares0
@johnsmith ·
Holy crap I'm glad you guys are a lot smarter than I am.
properties (22)
authorjohnsmith
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t051818954z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 05:18:15
last_update2016-07-20 05:18:15
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length56
author_reputation22,729,726,767,685
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id210,076
net_rshares0
@kingscrown ·
thats a both sided sword. users either wont be able to registr or will loose keys and loose money anyways.

the only way i see is 2FA, still complex but most frienldy from all of this
👍  ,
properties (23)
authorkingscrown
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t041129960z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-21 04:11:30
last_update2016-07-21 04:11:30
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length183
author_reputation2,115,151,300,228,565
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id238,025
net_rshares9,421,624,673
author_curate_reward""
vote details (2)
@kingtylervvs ·
WHY DON'T WE HAVE GOOGLE AUTHENTICATORS?
👍  
properties (23)
authorkingtylervvs
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t084531629z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 08:45:30
last_update2016-07-20 08:45:30
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length40
author_reputation356,176,599,126
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id213,753
net_rshares245,094,337
author_curate_reward""
vote details (1)
@liondani ·
$34.66
I will upvote every White Hat hackers post that will help us secure more our platform! And I hope that will give them the motivation to continue working for our security!
👍  , , , , , , ,
properties (23)
authorliondani
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002119711z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:21:18
last_update2016-07-20 00:21:18
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value28.624 HBD
curator_payout_value6.039 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length170
author_reputation95,095,146,236,111
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,095
net_rshares7,061,490,562,896
author_curate_reward""
vote details (8)
@liondani · (edited)
$1.41
can you get in touch with me on the slack channel?
(my name there is also liondani)

It is about a steemit user they "lost"  his owner key and needs desperately help @tonyson (lost owner key) now he posts under his new account @hien-tran read his post about the "hack" https://steemit.com/steemit/@hien-tran/i-wonder-if-you-could-help-me-with-my-account

co-founder of steemit @ned encouraged him to get in touch with you and that was a great idea in my opinion (I don't know if the reached already to you,his English are poor) I will appreciate it very much if you helped him "recover" his keys.... It is obvious that the funds he has lost are significant for him (he lives with his little Son in Vietnam)....  I can Imagine it will change his life if he can have access to his funds! Thanks in advance and please make a post about it so we can tip you for helping a dedicated community member. Thanks
👍  
properties (23)
authorliondani
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160723t132937748z
categorysteem
json_metadata{"tags":["steem"],"users":["tonyson","hien-tran","ned"],"links":["https://steemit.com/steemit/@hien-tran/i-wonder-if-you-could-help-me-with-my-account"]}
created2016-07-23 13:29:39
last_update2016-07-23 13:31:54
depth1
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.412 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length902
author_reputation95,095,146,236,111
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id296,674
net_rshares916,741,513,168
author_curate_reward""
vote details (1)
@robinhood ·
Sorry but I can't help this user - I checked my logs and @tonyson was not one of the accounts that I updated.  

The accounts I updated had their  keys changed to either `STM7kyb6WK6Sg9Eu4uu7WGqjYdqJzdBeKEWVDaDEKsgvhvESJZ1vM` or `STM65wH1LZ7BfSHcK69SShnqCAH5xdoSZpGkUjmzHJ5GCuxEK9V5G` which are the owner keys for @steemit and @steemit3 respectively.
properties (22)
authorrobinhood
permlinkre-liondani-re-robinhood-offline-attack-on-steem-user-credentials-20160723t212823000z
categorysteem
json_metadata{"tags":["steem"],"users":["tonyson","steemit","steemit3"]}
created2016-07-23 21:28:03
last_update2016-07-23 21:28:03
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length350
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id306,321
net_rshares0
@lukestokes ·
$1.49
Upvoting for visibility (and the Spaceballs reference), but not without much conflict. More people need to understand how serious password security is and the need for a good password manager. At the same time, I don't want to condone grey hat activity.

There were other ways to handle this that would have been true white hat. You could have checked those 500~ passwords, verified them, and then contacted the Steemit team privately. I've been posting in the Slack channel about the need for a private bug bounty program like Bugcrowd for exactly that purpose. There should also be an easy to find ethical disclosure procedure.

In this case, however, was it really Steemit's fault or a PEBKEC (Problem Exists Between Keyboard and Chair)? All attempts at creating idiot proof software fail as better idiots are produced.

I hope you can work with the Steemit team in an ethical manner in the future. I know I'm coming across as judgemental here, and it's possible you actually saved a lot of people from a lot of trouble. It still just _feels_ wrong. Either way, I wouldn't want to get on your bad side. :)
👍  , , , ,
properties (23)
authorlukestokes
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t214459451z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 21:45:00
last_update2016-07-19 21:45:00
depth1
children2
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.122 HBD
curator_payout_value0.364 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,108
author_reputation555,781,629,106,002
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id200,247
net_rshares711,664,755,526
author_curate_reward""
vote details (5)
@billbutler ·
$0.29
I don't fault the OP. This is a classic scenario where you don't fully comprehend the gravity unless it happens. I also like the fact that the OP is being financially compensated for his discovery. I hired my first CTO after he rooted our mail server!
👍  
properties (23)
authorbillbutler
permlinkre-lukestokes-re-robinhood-offline-attack-on-steem-user-credentials-20160720t003303825z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:33:03
last_update2016-07-20 00:33:03
depth2
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.294 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length251
author_reputation31,319,794,402,837
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,360
net_rshares161,012,470,617
author_curate_reward""
vote details (1)
@lukestokes ·
You might be right, Bill. I guess I'm just much more comfortable with white hat activities. We use BugCrowd for FoxyCart and have been very happy with the professionalism and ethics of those involved. When something is exposed (thankfully it's almost always some third party system outside of our PCI environment), it's hard not to take it very seriously. From what I've seen of the team here so far, I think they would have taken a white hat approach seriously also. But... maybe not. As I said, whether or not I like it, this approach may have saved quite a few people from even more frustration.
properties (22)
authorlukestokes
permlinkre-billbutler-re-lukestokes-re-robinhood-offline-attack-on-steem-user-credentials-20160720t005339974z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:53:39
last_update2016-07-20 00:53:39
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length598
author_reputation555,781,629,106,002
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,839
net_rshares0
@nabilov ·
make sure everyone participates in the first steemit lottery
https://i.imgflip.com/17okmb.jpg
https://steemit.com/money/@nabilov/the-first-steem-lottery-hosted-by-member-nabilov#comments
👎  
properties (23)
authornabilov
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t135302661z
categorysteem
json_metadata{"tags":["steem"],"image":["https://i.imgflip.com/17okmb.jpg"]}
created2016-07-20 13:53:06
last_update2016-07-20 13:53:06
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length186
author_reputation2,498,893,033,777
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id219,631
net_rshares-898,766,189,380
author_curate_reward""
vote details (1)
@ned ·
$0.99
robinhood, can you send me an email ned at steemit dot com
👍  , , , , , , ,
properties (23)
authorned
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t212321142z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 21:23:21
last_update2016-07-19 21:23:21
depth1
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.765 HBD
curator_payout_value0.226 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length58
author_reputation94,449,026,656,258
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id199,623
net_rshares520,556,982,735
author_curate_reward""
vote details (8)
@robinhood ·
$0.38
Sure.  Sent you a message a moment ago.  May hit your spam folder since it just said "hi".
👍  
properties (23)
authorrobinhood
permlinkre-ned-re-robinhood-offline-attack-on-steem-user-credentials-20160719t220638400z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 22:06:39
last_update2016-07-19 22:06:39
depth2
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.290 HBD
curator_payout_value0.094 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length90
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id200,793
net_rshares208,607,554,483
author_curate_reward""
vote details (1)
@neowenyuan27 ·
Steemit will grow bigger as a community. And with monetary rewards involved, we should expect and, maybe even accept people with different views and beliefs and motives.
 
From this post, it might just spell the beginning for many exciting things to happen here. Wherever exists blackhats, we just pray hard more whitehats appear. With the increasing popularity, this community will definitely grow, and perhaps its a good sign that @robinhood is here, helping us in his own ways. 

Even though, it indeed is wiser to leave the 'bad guys' to the 'cops'(devs), but i guess it doesn't suck if we have a @robinhood  around that we can trust, as this community grows. 

To the whitehats around!
properties (22)
authorneowenyuan27
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t142728397z
categorysteem
json_metadata{"tags":["steem"],"users":["robinhood"]}
created2016-07-20 14:27:33
last_update2016-07-20 14:27:33
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length690
author_reputation197,736,243,795
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id220,297
net_rshares0
@nioctib ·
upvote back the ones that upvote you
👍  
properties (23)
authornioctib
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t083545013z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-21 08:35:45
last_update2016-07-21 08:35:45
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length36
author_reputation85,098,617,111
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id241,715
net_rshares23,648,397
author_curate_reward""
vote details (1)
@oholiab ·
$0.31
That's pretty terrifying, and it's a good job that you posted this... It hadn't occurred that *of course* hashed passwords are going to be freely available offline because in using a web UI you're used to the assumptions of a traditional web model.

Good on you (assuming you did what you said) for just reassigning back to Steemit. Sounds like we do really need 2FA or generated only passwords... It's a shame that browser tooling around SSL client certs is so user unfriendly, having a client cert as a per-browser alternative to the generated password would be a good way of removing the usability barrier. Users would obviously still have to store their password but they could use the installed client cert for day-to-day auth and just use the password for requesting new certs for new devices.
👍  
properties (23)
authoroholiab
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t131338826z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 13:13:36
last_update2016-07-19 13:13:36
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.229 HBD
curator_payout_value0.076 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length799
author_reputation1,894,810,279,063
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id187,705
net_rshares165,747,762,904
author_curate_reward""
vote details (1)
@papa-pepper ·
The hacker is a scumbag and should get his legs broken or worse.  Quit treating him like a Knight in Shining armor.. He is nothing but lowlife gutter scum who caused a lot of people a lot of problems.  Thou shall not steal.  OP is nothing but an attention whore.
👎  
properties (23)
authorpapa-pepper
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t062859526z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 06:29:00
last_update2016-07-20 06:29:00
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length262
author_reputation1,951,223,832,091,597
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id211,438
net_rshares-339,256,336,586
author_curate_reward""
vote details (1)
@pierregi · (edited)
fds
properties (22)
authorpierregi
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t215549716z
categorysteem
json_metadata{"app":"hiveblog/0.1"}
created2016-07-20 21:55:48
last_update2025-06-22 21:25:42
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3
author_reputation11,429,270,871
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id230,736
net_rshares0
@rdwn ·
hopefully leaves a more lasting impression than yet another
👍  
properties (23)
authorrdwn
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t202200134z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 20:22:00
last_update2016-07-20 20:22:00
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length59
author_reputation-377,302,683,967
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id228,538
net_rshares150,288,816
author_curate_reward""
vote details (1)
@rogue91 ·
I think this is probably good to get such simple things done during the child life of a crypto less we have a dao scandal on steem in a year. lol
properties (22)
authorrogue91
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t232223218z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 23:22:24
last_update2016-07-19 23:22:24
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length145
author_reputation307,798,507,264
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id202,736
net_rshares0
@seanmchughart ·
Keep up the good work!!
properties (22)
authorseanmchughart
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t201309489z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 20:13:09
last_update2016-07-20 20:13:09
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length23
author_reputation258,090,606,596
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id228,306
net_rshares0
@seelemonsonline ·
I'm glad you didn't do anything malicious with this great power. Key management when left to the general public is likely dangerous. Hopefully if they lose money once, they'll learn their lesson.
properties (22)
authorseelemonsonline
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t203620348z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 20:36:18
last_update2016-07-20 20:36:18
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length195
author_reputation92,588,805,891
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id228,866
net_rshares0
@sharingtheworld ·
Hopefully steemit will realize this is something of HIGH relevance and importance, since most of the people don't know how to pick passwords (and most of those also use the same password for many identities: mail, facebook, and more). Thanks for your post, very appreciated!
👍  
properties (23)
authorsharingtheworld
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t034639588z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-21 03:46:39
last_update2016-07-21 03:46:39
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length274
author_reputation249,198,394,400
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id237,647
net_rshares102,101,603
author_curate_reward""
vote details (1)
@sigmajin · (edited)
im actually kind of suprised.  When they said that the hacker had private keys, i was thinking he could hashcat them to get passwords... but i figured with 16 characters that would take an unreasonable amount of time.  
I figured with a 16 digit password even the weakest passwords would be relatively hard to guess... though i do support 2FA
properties (22)
authorsigmajin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t172939451z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 17:29:36
last_update2016-07-19 17:32:15
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length342
author_reputation35,847,511,233,614
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id193,594
net_rshares0
@sigmajin ·
TBH, i think this is a pretty shitty thing to do.  It definitely isnt ethical hacking, and one can only hope that the owners pursue legal measures if your claims are true.
I agree with your point.. but i dont think you should be fucking with other peoples money to make it.
👍  
👎  
properties (23)
authorsigmajin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t174356207z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 17:43:54
last_update2016-07-19 17:43:54
depth1
children7
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length273
author_reputation35,847,511,233,614
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id193,921
net_rshares-108,959,783
author_curate_reward""
vote details (2)
@deedee ·
I'm actually shocked by this. There is really no legal distinction between "white hats" and "black hats". Nobody gave "robinhood" permission to hack 500 Steemit accounts. "robinhood", in fact, did "take the money"... since only "robinhood" now has access to these funds.
👎  
properties (23)
authordeedee
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t190217734z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 19:02:15
last_update2016-07-19 19:02:15
depth2
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length270
author_reputation2,532,149,863
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id195,898
net_rshares-184,854,226
author_curate_reward""
vote details (1)
@robinhood ·
$2.25
> since only "robinhood" now has access to these funds.

Incorrect, as I stated in my post, I updated these accounts to Steemit's key (not my key) so only Steemit has access to the funds.  This fact can be verified by inspecting the blockchain.
👍  , , , , ,
properties (23)
authorrobinhood
permlinkre-deedee-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t201405100z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 20:14:12
last_update2016-07-19 20:14:12
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.692 HBD
curator_payout_value0.554 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length244
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id197,747
net_rshares1,011,225,009,341
author_curate_reward""
vote details (6)
@robinhood ·
$135.45
Sigmajin, based on this comment and your last, I'm not sure you 100% understand the  situation.  

0. Regarding your first comment, I'm confused because if you can recover the private key you don't need the password.  Also, you are correct in assuming 16 chars can't be brute-forced attacked but it can be *dictionary* attacked.  If it was feasible to brute-force everyone would be screwed.
1. I didn't take these users money.  I re-assigned control of these user's accounts to Steemit which has a mechanism allowing them to establish new (hopefully better) credentials.
2. I'm curious what you would have regarded as more ethical in this instance?  Would doing nothing and watching these users get robbed be as ethical as merely burdening them with the  inconvience of being forced to pick a password that can't be trivially guessed?
👍  , , , , , , , , , , , ,
properties (23)
authorrobinhood
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t182327900z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 18:23:30
last_update2016-07-19 18:23:30
depth2
children2
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value101.616 HBD
curator_payout_value33.833 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length834
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id194,961
net_rshares15,583,634,124,240
author_curate_reward""
vote details (13)
@sigmajin · (edited)
OK, i was a little pissy bittrex is fucking with my money.
anyway 
1  yeah, i get that the private key obviates the need for the password here... my concern at the time was that after the users got their accounts back, the hacker could take the key, work their way backward to the users password, then use that password to attack other accounts.

2  SO what happens if the value of their assets decreases by 50%  while theyre messing around with password recovery?

3  You could have proved your point by contacting tptb with the password list.  Or upvoting this post.. or running some kind of script to make them all post horse pornography every few hours until they changed their password.

I know if it happened to me, id be pissed (even though i dont keep a ton of money here)... i guess im not behind it but i realize it was well intentioned.
properties (22)
authorsigmajin
permlinkre-robinhood-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t184706056z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 18:47:03
last_update2016-07-19 19:04:12
depth3
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length847
author_reputation35,847,511,233,614
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id195,523
net_rshares0
@robinhood ·
$0.85
Also 

4. I'm not the hacker from 2015-07-14 (I was unclear from your reply if you grasped this).  His/her attack vector was totally different.
👍  
properties (23)
authorrobinhood
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t183123000z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-19 18:31:27
last_update2016-07-19 18:31:27
depth2
children1
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.634 HBD
curator_payout_value0.211 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length143
author_reputation2,618,720,866,038
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id195,176
net_rshares430,517,939,403
author_curate_reward""
vote details (1)
@sigmajin · (edited)
yeah, dk if you saw my post pointing it out but i think the 7-14 attack came from @goodgame...  the script he was using is still in all of his posts if its him, and the domain it was pinging (steemit.uk) was regged that day.  https://steemit.com/doyourpart/@sigmajin/um-this-guy-is-trying-to-do-something-bad-right
properties (22)
authorsigmajin
permlinkre-robinhood-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t190231878z
categorysteem
json_metadata{"tags":["steem"],"links":["https://steemit.com/doyourpart/@sigmajin/um-this-guy-is-trying-to-do-something-bad-right"]}
created2016-07-19 19:02:27
last_update2016-07-19 19:02:45
depth3
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length314
author_reputation35,847,511,233,614
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id195,905
net_rshares0
@skorss ·
great to see someone getting on the topic and doing something about it, this was completely necessary
properties (22)
authorskorss
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t053913488z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 05:39:18
last_update2016-07-20 05:39:18
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length101
author_reputation590,420,193,253
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id210,493
net_rshares0
@steemitboard ·
Congratulations @robinhood! You received a personal award!

<table><tr><td>https://steemitimages.com/70x70/http://steemitboard.com/@robinhood/birthday3.png</td><td>Happy Birthday! - You are on the Steem blockchain for 3 years!</td></tr></table>

<sub>_You can view [your badges on your Steem Board](https://steemitboard.com/@robinhood) and compare to others on the [Steem Ranking](https://steemitboard.com/ranking/index.php?name=robinhood)_</sub>


###### [Vote for @Steemitboard as a witness](https://v2.steemconnect.com/sign/account-witness-vote?witness=steemitboard&approve=1) to get one more award and increased upvotes!
properties (22)
authorsteemitboard
permlinksteemitboard-notify-robinhood-20190719t040656000z
categorysteem
json_metadata{"image":["https://steemitboard.com/img/notify.png"]}
created2019-07-19 04:06:57
last_update2019-07-19 04:06:57
depth1
children0
last_payout2019-07-26 04:06:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length624
author_reputation38,975,615,169,260
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id88,474,605
net_rshares0
@theemperor ·
Look at you, so young and carefree :-)
properties (22)
authortheemperor
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t030851132z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-21 03:11:03
last_update2016-07-21 03:11:03
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length38
author_reputation8,736,015,906
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id237,011
net_rshares0
@tosch ·
http://keepass.info/
properties (22)
authortosch
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t063415807z
categorysteem
json_metadata{"tags":["steem"],"links":["http://keepass.info/"]}
created2016-07-20 06:34:15
last_update2016-07-20 06:34:15
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation3,148,075,991,236
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id211,513
net_rshares0
@tuck-fheman ·
$0.73
Nice job and thanks!
👍  , ,
properties (23)
authortuck-fheman
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002054622z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 00:20:57
last_update2016-07-20 00:20:57
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.567 HBD
curator_payout_value0.160 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation345,778,813,561,569
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id204,084
net_rshares406,358,632,134
author_curate_reward""
vote details (3)
@williambanks ·
$0.82
I can say nothing here except thank you!  This really should be the most upvoted topic of the day.  Here's an upvote from me!
👍  
properties (23)
authorwilliambanks
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t021007790z
categorysteem
json_metadata{"tags":["steem"]}
created2016-07-20 02:10:09
last_update2016-07-20 02:10:09
depth1
children0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.612 HBD
curator_payout_value0.204 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length125
author_reputation90,708,691,850,244
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id206,543
net_rshares417,493,850,561
author_curate_reward""
vote details (1)