create account

Security: Watch out, this is Steem by tarazkp

View this thread on: hive.blogpeakd.comecency.com
· @tarazkp · (edited)
$28.40
Security: Watch out, this is Steem
There is another phishing attack ongoing and unfortunately @surfermarly, one of the most experienced members of the community was caught out. Thankfully, she has control of her account back from one of the assholes who do these kinds of things. You can can see details of this particular phishing approach [here in a post](https://steemit.com/steemit/@arcange/phishing-attempts-are-running-and-use-fake-comments-with-images) by @arcange. Sadly, everyone must remain vigilant at all times because big or small, due to the value in wallets, we are all targets.

![20180918_204902.jpg](https://cdn.steemitimages.com/DQma2khkAgSKrQ4YLn4So48kkRGn8eoaiiAY5GuMVcJuxnn/20180918_204902.jpg)

However, this should also send more alarm bells ringing than vigilance because of it can happen to an experienced user, it can happen to anyone and often does. 

Most people aren't used to having to protect keys in this way and they aren't used to bring on a decentralised system where recovery isn't easy. Most are also not accustomed to being direct targets and very few on earth are used to being targeted openly and publicly. 

This is Steem and *all* of crypto it seems and is an obvious drawback of allowing close to total anonymity. But something must be done on Steem *if* we are going to ever mainstream this community. 

The system is complex in itself but I am sure there are many people who do not understand their keys and why and where to use them. The amount of people who lose their master is very high which is a symptom (and risk) of being used to having a centralised authority to message behind a *"lost password?"* link. 

In Steem there is a lot more responsibility put on the individual than on other platforms and no clear guidelines of how best to organise security maintenance. Keep your keys safe and offline is good advice but considering people are accessing their accounts from multiple points as well as mobile devices, very impractical. 

From my understanding (I have recently heard), 2FA is not possible for some reason, but there must be other ways that can be used to protect an account even in the event of a lost key. 

The problem is that mass adoption means many people coming onto the platform who are a lot less security conscience than the average crypto enthusiast and on an immutable blockchain, the number of stolen and dead accounts is going to grow rapidly. It is going to be a tough sell to keep explaining why we can do nothing about theft and we offer no real preventative protection against it for the *average* user. 

There is a high learning curve here already but is it wise to have the idea of security and watch out for bad actors the first lesson learned coming into a community? If the experienced struggle with this, what hope do the newbies have? Not everyone should have to learn the hard way when it comes to account security and their should be some clear advice and solutions available that even the most basic user can understand considering this is a global community. 

I am unsure what is in the pipeline for security measures but in my opinion, a lot more needs to be developed to both simplify account management and complicate account theft before a million more people come I and lose their keys to a phishing attack in their first week and have their account turned into one of the soldiers in a bot army.

Online security is a difficult area because often it requires some level of centralisation which becomes a weak and contentious point in a decentralised community. There is some kind of *lesser of two evils* concept at play but I am unsure which is the larger evil of the two. 

Until something is in place though, everyone has to remain on guard at all times and of something seems out of place like a login screen, it probably is it of place and should be treated with extreme caution. There are always going to be bad actors on Steem and in the world and this is why having a healthy and supportive community inherently provides some measure of security to protect its members. 

*All for one, one for all.*

What are your thoughts on security on Steem and do you have any good advice or trusted tools to maintain security across devices?

Taraz 
[ a Steem original ]
<sub>(posted from phone)</sub>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 78 others
properties (23)
authortarazkp
permlinksecurity-watch-out-this-is-steem
categorysecurity
json_metadata{"tags":["security","steem","phishing","community","future"],"users":["surfermarly","arcange"],"image":["https://cdn.steemitimages.com/DQma2khkAgSKrQ4YLn4So48kkRGn8eoaiiAY5GuMVcJuxnn/20180918_204902.jpg"],"links":["https://steemit.com/steemit/@arcange/phishing-attempts-are-running-and-use-fake-comments-with-images"],"app":"steemit/0.1","format":"markdown"}
created2018-09-18 18:43:39
last_update2018-09-19 08:15:54
depth0
children42
last_payout2018-09-25 18:43:39
cashout_time1969-12-31 23:59:59
total_payout_value21.899 HBD
curator_payout_value6.496 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,266
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,608,424
net_rshares22,103,783,919,681
author_curate_reward""
vote details (142)
@cryptoandcoffee ·
$0.03
We have to keep an eye out for everyone as it happens. I wish there was some other barrier of security that could be found. I know the power down takes 13 weeks but when Steem rockets this place would be like hitting a bank. It will become more serious than a few thousand dollars as we are talking in some cases millions.
👍  
properties (23)
authorcryptoandcoffee
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t185218697z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 18:52:21
last_update2018-09-18 18:52:21
depth1
children3
last_payout2018-09-25 18:52:21
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length322
author_reputation3,573,385,714,783,742
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,608,952
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@tarazkp ·
$0.02
people can have Steem sitting in their wallet liquid too and sometimes, that is quite a lot. I am not sure what solutions are available but even a simple secondary pin with 3 attempts might be enough for most cases. Re-login would need master and come with an additional warning that the pin was inputted wrongly and to change the keys if it wasn't you.
👍  ,
properties (23)
authortarazkp
permlinkre-cryptoandcoffee-re-tarazkp-security-watch-out-this-is-steem-20180918t185809230z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 18:58:03
last_update2018-09-18 18:58:03
depth2
children2
last_payout2018-09-25 18:58:03
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.003 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length353
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,609,278
net_rshares21,133,424,463
author_curate_reward""
vote details (2)
@cryptoandcoffee ·
Just don't understand. If you are not going to power up then stick it into savings. It doesn't matter if it is going to take 3 days to get it out, better safe than sorry.
properties (22)
authorcryptoandcoffee
permlinkre-tarazkp-re-cryptoandcoffee-re-tarazkp-security-watch-out-this-is-steem-20180918t191921862z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:19:24
last_update2018-09-18 19:19:24
depth3
children1
last_payout2018-09-25 19:19:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length170
author_reputation3,573,385,714,783,742
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,610,640
net_rshares0
@empress-eremmy ·
$0.04
People are despicable. Thanks for the heads up, I really am taking it a lot more seriously now
👍  
properties (23)
authorempress-eremmy
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t215950565z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 22:00:09
last_update2018-09-18 22:00:09
depth1
children0
last_payout2018-09-25 22:00:09
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length94
author_reputation537,410,962,648,252
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,620,129
net_rshares28,697,302,520
author_curate_reward""
vote details (1)
@empress-eremmy ·
$0.03
People are despicable. Thanks for the heads up, I really am taking it a lot more seriously now
👍  
properties (23)
authorempress-eremmy
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t220126443z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 22:01:39
last_update2018-09-18 22:01:39
depth1
children1
last_payout2018-09-25 22:01:39
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.003 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length94
author_reputation537,410,962,648,252
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,620,228
net_rshares28,611,815,084
author_curate_reward""
vote details (1)
@tarazkp ·
>People are despicable.

the "benefits" of having value on a platform... ;)
properties (22)
authortarazkp
permlinkre-empress-eremmy-re-tarazkp-security-watch-out-this-is-steem-20180918t221348553z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 22:13:39
last_update2018-09-18 22:13:39
depth2
children0
last_payout2018-09-25 22:13:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length75
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,620,898
net_rshares0
@enjoywithtroy ·
$0.03
I feel so sorry for @surfermarly in the attack.   In a separate incident @kryptocoin got hacked as you can read about [here](https://steemit.com/familyprotection/@kryptocoin/hacked-when-you-get-pushed-out-of-your-own-house-by-an-impostor).  Many months ago I was scamed 663 SBD by some Romnians. in a phising.   One must be VERY careful.   I learned the importance of not using your master key.   Folks need to be educated about this. Decentralization is like the wild west of the internet. LoL Thanks my friend.
👍  
properties (23)
authorenjoywithtroy
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t192623188z
categorysecurity
json_metadata{"tags":["security"],"users":["surfermarly","kryptocoin"],"links":["https://steemit.com/familyprotection/@kryptocoin/hacked-when-you-get-pushed-out-of-your-own-house-by-an-impostor"],"app":"steemit/0.1"}
created2018-09-18 19:27:57
last_update2018-09-18 19:27:57
depth1
children2
last_payout2018-09-25 19:27:57
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length512
author_reputation142,851,883,439,160
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id71,611,144
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@tarazkp ·
>Decentralization is like the wild west of the internet

Don't trust anyone ever.
properties (22)
authortarazkp
permlinkre-enjoywithtroy-re-tarazkp-security-watch-out-this-is-steem-20180918t193226760z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:32:18
last_update2018-09-18 19:32:18
depth2
children1
last_payout2018-09-25 19:32:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length81
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,380
net_rshares0
@por500bolos ·
$0.04
> Don't trust anyone ever.

**Unless...** you want to consult with *experts* who **really know. };)**

![Security_Check.jpg](https://cdn.steemitimages.com/DQmcwjwoMtbtfFsDaKEH6BN2JhkM8T2YoH1iAuGjjJrtupM/Security_Check.jpg)
👍  
properties (23)
authorpor500bolos
permlinkre-tarazkp-re-enjoywithtroy-re-tarazkp-security-watch-out-this-is-steem-20180919t014311610z
categorysecurity
json_metadata{"tags":["security"],"image":["https://cdn.steemitimages.com/DQmcwjwoMtbtfFsDaKEH6BN2JhkM8T2YoH1iAuGjjJrtupM/Security_Check.jpg"],"app":"steemit/0.1"}
created2018-09-19 01:43:12
last_update2018-09-19 01:43:12
depth3
children0
last_payout2018-09-26 01:43:12
cashout_time1969-12-31 23:59:59
total_payout_value0.029 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length222
author_reputation14,975,733,879,671
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,632,084
net_rshares28,697,302,520
author_curate_reward""
vote details (1)
@hlezama · (edited)
$0.03
I was going to ask if for the security aspect of Steemit is discussed during the Steem gatherings (fests?). If there were talents capable of developing something as complex as blockchain, my guess is there gotta be equal or better talents to counter attack and protect this thing.
I know nothing about tech and i don't think with the meager resources we have at hand here i'll be able to learn or have access to any kind of security measures, unless the paltform develops methods to protect everybody.
Yesterday, precisely i was asked by an alleged member of the cervantes group to participate on an alleged program of delegation (i had been allegedly chosen to have a chance). He sent me the link to a @cervantes post showing the first month's winner and all. It so happens that that user is not @pgarcgo #0325, his discord number was different. I did not know @cervantes had already issued a warning or something like that. I wonder if that "user" has been tracked down and blocked or something.
👍  
properties (23)
authorhlezama
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t193601972z
categorysecurity
json_metadata{"tags":["security"],"users":["cervantes","pgarcgo"],"app":"steemit/0.1"}
created2018-09-18 19:36:03
last_update2018-09-18 19:37:36
depth1
children2
last_payout2018-09-25 19:36:03
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length997
author_reputation265,529,475,623,172
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,641
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@tarazkp ·
>I know nothing about tech and i don't think with the meager resources we have at hand here i'll be able to learn or have access to any kind of security measures, 

- never use your master key unless changing your other keys. Keep it offline. 
- only log in with your posting key
- only use your active key for transfers
- never give them to anyone.
properties (22)
authortarazkp
permlinkre-hlezama-re-tarazkp-security-watch-out-this-is-steem-20180918t194012050z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:40:03
last_update2018-09-18 19:40:03
depth2
children1
last_payout2018-09-25 19:40:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length349
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,872
net_rshares0
@hlezama ·
Thanks, @tarazkp
properties (22)
authorhlezama
permlinkre-tarazkp-re-hlezama-re-tarazkp-security-watch-out-this-is-steem-20180918t195138663z
categorysecurity
json_metadata{"tags":["security"],"users":["tarazkp"],"app":"steemit/0.1"}
created2018-09-18 19:51:39
last_update2018-09-18 19:51:39
depth3
children0
last_payout2018-09-25 19:51:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length16
author_reputation265,529,475,623,172
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,612,572
net_rshares0
@ladyrebecca ·
$0.03
A good thing you brought up this story - been sort of busy and I didn't look into details earlier - using a name with great rep that's pretty smart... The shock of seeing such a message from someone important could easily make you ignore the risks you are normally aware.
As for the masses hopefully joining Steemit - security would definitely be a problem... if people keep losing their keys, word would spread the site is not safe.. which wouldn't be good!
👍  
properties (23)
authorladyrebecca
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t194302096z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:43:24
last_update2018-09-18 19:43:24
depth1
children1
last_payout2018-09-25 19:43:24
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length458
author_reputation122,127,717,116,461
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,612,066
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@tarazkp ·
The shock of seeing such a message from someone important could easily make you ignore the risks you are normally aware.

It is a type of greed. I am not saying in this particular case but it plays on the trigger. Same in chats when *"Vhales"* promise votes etc for a few SBD transferred to blocktrades. The want for it to be real overpowers the rational mind.
properties (22)
authortarazkp
permlinkre-ladyrebecca-re-tarazkp-security-watch-out-this-is-steem-20180918t194729701z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:47:21
last_update2018-09-18 19:47:21
depth2
children0
last_payout2018-09-25 19:47:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length360
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,612,314
net_rshares0
@lauram ·
We must protect our key to avoid checkmate friends, since there are many cheats in digital questions. My greetings, @tarazkp.
properties (22)
authorlauram
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t185955353z
categorysecurity
json_metadata{"tags":["security"],"users":["tarazkp"],"app":"steemit/0.1"}
created2018-09-18 18:59:51
last_update2018-09-18 18:59:51
depth1
children0
last_payout2018-09-25 18:59:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length125
author_reputation1,921,696,906,491
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,609,397
net_rshares0
@lovepreet2511 ·
I don't share my key with anyone but I am afraid about it is there any way we can keep our account safe
properties (22)
authorlovepreet2511
permlinkre-tarazkp-security-watch-out-this-is-steem-20180919t065811467z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-19 06:58:12
last_update2018-09-19 06:58:12
depth1
children0
last_payout2018-09-26 06:58:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length103
author_reputation1,149,150,491,604
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,650,814
net_rshares0
@manoldonchev ·
$0.03
Actually a few good ideas to prevent abuse are in place on steemit and I like them so much. I haven't yet reached a point to try and withdraw any funds but I like the time limitations - the SP withdrawal limit of 1/13 per day makes me feel much more secure than in a case I witnessed a few years ago.

My third person view:
In 2008 my roommates started digging bitcoins. It required about 500 Euro only for a good enough machine. I was about to invest in one. My roomies had already acquired - in a matter of weeks -  a few bitcoins per person which now would be worth a small fortune. One day the system got hacked, their few bitcoins drained immediately and although it took a short time to get the system running again, few people had the courage to dedicate resources again. I didn't even start.

I've been stolen from in real life - a few bikes, guitars, thing like these. Still it felt very bad. Not because of the money but because of the unexpected insult to my hard work related beliefs.
👍  
properties (23)
authormanoldonchev
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t192706558z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:27:03
last_update2018-09-18 19:27:03
depth1
children2
last_payout2018-09-25 19:27:03
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length996
author_reputation292,116,483,961,241
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,100
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@tarazkp ·
>the SP withdrawal limit of 1/13 per day makes me feel much more secure than in a case I witnessed a few years ago.

per *week*

>I've been stolen from in real life - a few bikes, guitars, thing like these. Still it felt very bad. Not because of the money but because of the unexpected insult to my hard work related beliefs.

It is a personal violation and intentional which makes it worse.
properties (22)
authortarazkp
permlinkre-manoldonchev-re-tarazkp-security-watch-out-this-is-steem-20180918t193138250z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:31:30
last_update2018-09-18 19:31:30
depth2
children1
last_payout2018-09-25 19:31:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length391
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,342
net_rshares0
@manoldonchev ·
$0.03
Yup, exactly that - the personal violation. It stays the same even online. I guess I should learn to use the alternative keys and not the master. Thank you very much for bringing up the issue :)

My wish on the matter of decentralization is for the community to find enough strength and produce enough ideas so that it proves decentralized can still be secure. That would be so much more than just a social network benefit.
👍  
properties (23)
authormanoldonchev
permlinkre-tarazkp-re-manoldonchev-re-tarazkp-security-watch-out-this-is-steem-20180918t200542238z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 20:05:39
last_update2018-09-18 20:05:39
depth3
children0
last_payout2018-09-25 20:05:39
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.001 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length423
author_reputation292,116,483,961,241
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,613,444
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@mattclarke ·
$0.30
Good news on that front actually. There's a browser extension almost released, (commissioned by a couple of the witnesses). It holds your keys in your browser and just sends a token through the net.
Your keys never actually leave your browser.
Its like metamask for Ethereum.
I've been using it for a week or so and it's really top notch. Not sure when official launch will be, but I'd say very soon.
👍  , , , ,
properties (23)
authormattclarke
permlinkre-tarazkp-security-watch-out-this-is-steem-20180918t190027384z
categorysecurity
json_metadata{"tags":["security"],"community":"steempeak","app":"steempeak"}
created2018-09-18 19:00:30
last_update2018-09-18 19:00:30
depth1
children5
last_payout2018-09-25 19:00:30
cashout_time1969-12-31 23:59:59
total_payout_value0.256 HBD
curator_payout_value0.046 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length400
author_reputation127,126,990,436,054
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,609,444
net_rshares259,704,242,833
author_curate_reward""
vote details (5)
@tarazkp ·
That s awesome, by any chance does it work on mobile?
properties (22)
authortarazkp
permlinkre-mattclarke-re-tarazkp-security-watch-out-this-is-steem-20180918t190408439z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 19:04:00
last_update2018-09-18 19:04:00
depth2
children4
last_payout2018-09-25 19:04:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length53
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,609,648
net_rshares0
@mattclarke · (edited)
$0.03
I haven't tried, tbh. I use the Brave browser on my mobile, and I don't imagine it's compatible yet. 
It works great in chrome on my desktop though.
Not sure about steemit.com, but I know steempeak.com and steemmonsters.com are testing it out.
I've used it on both and it's heaps quicker and simpler than steemconnect.
👍  
properties (23)
authormattclarke
permlinkre-tarazkp-re-mattclarke-re-tarazkp-security-watch-out-this-is-steem-20180918t192919083z
categorysecurity
json_metadata{"tags":["security"],"community":"steempeak","app":"steempeak"}
created2018-09-18 19:29:21
last_update2018-09-18 19:31:00
depth3
children3
last_payout2018-09-25 19:29:21
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.001 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length318
author_reputation127,126,990,436,054
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,611,219
net_rshares28,601,176,883
author_curate_reward""
vote details (1)
@minismallholding · (edited)
$0.03
I notice that links that take you away from Steemit have a little symbol to let you know. I wonder if this was hidden, somehow, in this case. Perhaps this could be extended to a warning when you click on it to say you are being diverted to a different site. Admittedly, it could get annoying if you click on links a lot, though.
👍  
properties (23)
authorminismallholding
permlinkre-tarazkp-security-watch-out-this-is-steem-20180919t133508924z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-19 13:35:06
last_update2018-09-20 00:51:30
depth1
children2
last_payout2018-09-26 13:35:06
cashout_time1969-12-31 23:59:59
total_payout_value0.022 HBD
curator_payout_value0.007 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length328
author_reputation296,511,339,642,720
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,676,497
net_rshares22,916,520,063
author_curate_reward""
vote details (1)
@tarazkp ·
I think it was an image cut and paste from a real comment. Never use your master.
properties (22)
authortarazkp
permlinkre-minismallholding-re-tarazkp-security-watch-out-this-is-steem-20180919t180258366z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-19 18:02:51
last_update2018-09-19 18:02:51
depth2
children1
last_payout2018-09-26 18:02:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length81
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,696,294
net_rshares0
@minismallholding ·
Even images have the little symbol in the corner. They must have been pretty clever to get around that somehow. 
Yes, most certainly never user your master and really check the address bar. You are so right, though, it's not going to help with onboarding in the long run. Even the pass keys are off putting to many. It needs to be a bit simpler and safer.
properties (22)
authorminismallholding
permlinkre-tarazkp-re-minismallholding-re-tarazkp-security-watch-out-this-is-steem-20180920t005504267z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 00:55:00
last_update2018-09-20 00:55:00
depth3
children0
last_payout2018-09-27 00:55:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length355
author_reputation296,511,339,642,720
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,719,803
net_rshares0
@steem-ua ·
$0.04
#### Hi @tarazkp!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your **UA** account score is currently 6.118 which ranks you at **#253** across all Steem accounts.
Your rank has improved 3 places in the last three days (old rank 256).

In our last Algorithmic Curation Round, consisting of 516 contributions, your post is ranked at **#17**.
##### Evaluation of your UA score:

* You've built up a nice network.
* The readers appreciate your great work!
* Great user engagement! You rock!


**Feel free to join our [@steem-ua Discord server](https://discord.gg/KpBNYGz)**
👍  
properties (23)
authorsteem-ua
permlinkre-security-watch-out-this-is-steem-20180921t150008z
categorysecurity
json_metadata"{"app": "beem/0.19.54"}"
created2018-09-21 15:00:09
last_update2018-09-21 15:00:09
depth1
children0
last_payout2018-09-28 15:00:09
cashout_time1969-12-31 23:59:59
total_payout_value0.029 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length628
author_reputation23,214,230,978,060
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,864,577
net_rshares28,724,328,561
author_curate_reward""
vote details (1)
@surfermarly ·
$0.03
**Thanks a lot for bringing this up!**
We can't talk often enough about security measures and educate the community. I did a huge mistake and stepped into a really uncool trap - which then taught me for life, so I'm glad to share my experience with and warn others now.

*Appreciated & resteemed*
👍  
properties (23)
authorsurfermarly
permlinkre-tarazkp-security-watch-out-this-is-steem-20180920t190944882z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 19:09:48
last_update2018-09-20 19:09:48
depth1
children5
last_payout2018-09-27 19:09:48
cashout_time1969-12-31 23:59:59
total_payout_value0.029 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length296
author_reputation318,958,646,866,746
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,792,563
net_rshares28,697,302,520
author_curate_reward""
vote details (1)
@tarazkp ·
$0.05
It is a challenge because compared to 'normal sites', there is more complexity here and not a great deal of clear communication. Combine that with some clever scammers and it is unfortunately going to be more and more of an issue moving forward with mainstreaming.
👍  
properties (23)
authortarazkp
permlinkre-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t191227063z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 19:12:21
last_update2018-09-20 19:12:21
depth2
children1
last_payout2018-09-27 19:12:21
cashout_time1969-12-31 23:59:59
total_payout_value0.039 HBD
curator_payout_value0.012 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length264
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,792,729
net_rshares39,611,353,781
author_curate_reward""
vote details (1)
@surfermarly · (edited)
Absolutely, only having a serious of different keys (compared to one password you usually have on other social media sites) makes it incredibly complex. Sometimes it's not even about not being informed, but being distracted - like it happened to me twice. A couple of weeks back, I accidentally introduced my active key into the *memo* field of the smartsteem promotion service. At that point in time, there was no alert implemented yet, that informed you when you accidentally typed something into the field that looked like a key. I lost 18 SBD which was not much, but still a lesson. As a positive takeaway, the website was updated and now people are warned when introducing a key into the wrong field (like it was already implemented on steemit.com before).

The second time (as you mentioned here) I was provided with a phishing link that was wearing such a good make-up that already 850 other users had been fallen for it (as I learned later on from a developer). Eight hundred fifty people! 

Now the no. 1 rule is surely to NEVER use the wrong key. That can prevent us from a lot of trouble.

Total security doesn't exist when human beings are involved - as in real life so online. However, I feel that there's a big lack of education and we should start a whole campaign to better inform those who join us. 

Btw I was desperately trying to find some information in the Steemit FAQ on how to safely STORE keys. It's just said that they should be stored safely / offline, but a non-crypto person would never understand at first glance what that actually means...

Again, thanks for bringing this up! We need more of it :-)
properties (22)
authorsurfermarly
permlinkre-tarazkp-re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180921t064520864z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-21 06:45:24
last_update2018-09-21 06:47:36
depth3
children0
last_payout2018-09-28 06:45:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,630
author_reputation318,958,646,866,746
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,831,758
net_rshares0
@tobixen ·
I also had a close run a couple of years ago, with Localbitcoins.  I'm considering myself as an expert, so I found it quite embarrassing, but it sort of proves the point that even experienced users may fall for phishing.

I got a phishing email, opened it on my mobile.  Now, on my regular desktop email client (mutt), I can quite easily detect phishing-attempts, but on the mobile details like the senders email address and what email server it came from was hidden.  In addition I was trying to pay attention to a real life talk, and in addition I was drinking beer and not being completely sober ... so I followed a link urging me to log into my localbitcoins account.  So the phisherman got my password.  Luckily Localbitcoins have an extra measure of security by cookies, they don't allow logins from a new browser without the account holder first confirming it by email, so when I got a "confirm this login alert", I understood that I had been phished, didn't lose anything and could change my password simply.
properties (22)
authortobixen
permlinkre-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t200842179z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 20:08:42
last_update2018-09-20 20:08:42
depth2
children1
last_payout2018-09-27 20:08:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,016
author_reputation18,276,555,395,725
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,796,079
net_rshares0
@surfermarly ·
Thanks for being so open @tobixen, and I'm grateful you mentioned that the experience can not protect us. Especially phishing links are quite elaborated nowadays, and a single second of distraction may drive you right into a big disaster. 

Steem users log-in themselves from different devices every day, and I'm pretty sure that this is one of the biggest security gaps. I have no keys on my phone anymore, but sometimes it's annoying that I can't upvote or comment posts while I'm on the move.

It's hard to define a well working synergy of flexibility, efficiency and security. Probably we can't have them all.
properties (22)
authorsurfermarly
permlinkre-tobixen-re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180921t070819284z
categorysecurity
json_metadata{"tags":["security"],"users":["tobixen"],"app":"steemit/0.1"}
created2018-09-21 07:08:24
last_update2018-09-21 07:08:24
depth3
children0
last_payout2018-09-28 07:08:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length613
author_reputation318,958,646,866,746
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,833,019
net_rshares0
@tobixen ·
I also had a close run a couple of years ago, with Localbitcoins.  I'm considering myself as an expert, so I found it quite embarrassing, but it sort of proves the point that even experienced users may fall for phishing.

I got a phishing email, opened it on my mobile.  Now, on my regular desktop email client (mutt), I can quite easily detect phishing-attempts, but on the mobile details like the senders email address and what email server it came from was hidden.  In addition I was trying to pay attention to a real life talk, and in addition I was drinking beer and not being completely sober ... so I followed a link urging me to log into my localbitcoins account.  So the phisherman got my password.  Luckily Localbitcoins have an extra measure of security by cookies, they don't allow logins from a new browser without the account holder first confirming it by email, so when I got a "confirm this login alert", I understood that I had been phished, didn't lose anything and could change my password simply.
properties (22)
authortobixen
permlinkre-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t201103308z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 20:11:06
last_update2018-09-20 20:11:06
depth2
children0
last_payout2018-09-27 20:11:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,016
author_reputation18,276,555,395,725
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,796,222
net_rshares0
@tezmel ·
$0.03
Sometimes this turns into a fear. I have nothing to be 'syphoned' currently but I wonder what will happen when I do. I can imagine how painful it is for someone who has gone through it. 

Posted using [Partiko Android](https://steemit.com/@partiko-android)
👍  
properties (23)
authortezmel
permlinktezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t210151883z
categorysecurity
json_metadata{"app":"partiko"}
created2018-09-18 21:01:51
last_update2018-09-18 21:01:51
depth1
children2
last_payout2018-09-25 21:01:51
cashout_time1969-12-31 23:59:59
total_payout_value0.022 HBD
curator_payout_value0.007 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length256
author_reputation111,344,076,038,127
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,616,607
net_rshares22,889,452,067
author_curate_reward""
vote details (1)
@tarazkp ·
gotta stay frosty in the Steem jungle :)
properties (22)
authortarazkp
permlinkre-tezmel-tezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t213755035z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-18 21:37:48
last_update2018-09-18 21:37:48
depth2
children1
last_payout2018-09-25 21:37:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length40
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,618,886
net_rshares0
@tezmel ·
$0.04
So it seems! Sigh.

Posted using [Partiko Android](https://steemit.com/@partiko-android)
👍  
properties (23)
authortezmel
permlinktezmel-re-tarazkp-re-tezmel-tezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t223239911z
categorysecurity
json_metadata{"app":"partiko"}
created2018-09-18 22:32:39
last_update2018-09-18 22:32:39
depth3
children0
last_payout2018-09-25 22:32:39
cashout_time1969-12-31 23:59:59
total_payout_value0.028 HBD
curator_payout_value0.007 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length88
author_reputation111,344,076,038,127
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,621,817
net_rshares28,611,815,084
author_curate_reward""
vote details (1)
@tobixen ·
Steem does have some tools in the toolbox, like the "saving account", the fact that it takes long time to "power down", plus the account recovery feature
properties (22)
authortobixen
permlinkre-tarazkp-security-watch-out-this-is-steem-20180920t200333415z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 20:03:33
last_update2018-09-20 20:03:33
depth1
children0
last_payout2018-09-27 20:03:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length153
author_reputation18,276,555,395,725
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,795,775
net_rshares0
@v4vapid ·
$0.04
USE YOUR POSTING KEY for everyday use!
👍  
properties (23)
authorv4vapid
permlinkre-tarazkp-security-watch-out-this-is-steem-20180919t015619773z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-19 01:56:21
last_update2018-09-19 01:56:21
depth1
children1
last_payout2018-09-26 01:56:21
cashout_time1969-12-31 23:59:59
total_payout_value0.029 HBD
curator_payout_value0.008 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length38
author_reputation227,173,587,450,152
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,632,841
net_rshares28,697,302,520
author_curate_reward""
vote details (1)
@tarazkp ·
Indeed. it is amazing how many use their master for *convenience.*
properties (22)
authortarazkp
permlinkre-v4vapid-re-tarazkp-security-watch-out-this-is-steem-20180920t190953276z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-20 19:09:48
last_update2018-09-20 19:09:48
depth2
children0
last_payout2018-09-27 19:09:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length66
author_reputation5,837,594,903,387,606
root_title"Security: Watch out, this is Steem"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id71,792,566
net_rshares0