There is another phishing attack ongoing and unfortunately @surfermarly, one of the most experienced members of the community was caught out. Thankfully, she has control of her account back from one of the assholes who do these kinds of things. You can can see details of this particular phishing approach [here in a post](https://steemit.com/steemit/@arcange/phishing-attempts-are-running-and-use-fake-comments-with-images) by @arcange. Sadly, everyone must remain vigilant at all times because big or small, due to the value in wallets, we are all targets.  However, this should also send more alarm bells ringing than vigilance because of it can happen to an experienced user, it can happen to anyone and often does. Most people aren't used to having to protect keys in this way and they aren't used to bring on a decentralised system where recovery isn't easy. Most are also not accustomed to being direct targets and very few on earth are used to being targeted openly and publicly. This is Steem and *all* of crypto it seems and is an obvious drawback of allowing close to total anonymity. But something must be done on Steem *if* we are going to ever mainstream this community. The system is complex in itself but I am sure there are many people who do not understand their keys and why and where to use them. The amount of people who lose their master is very high which is a symptom (and risk) of being used to having a centralised authority to message behind a *"lost password?"* link. In Steem there is a lot more responsibility put on the individual than on other platforms and no clear guidelines of how best to organise security maintenance. Keep your keys safe and offline is good advice but considering people are accessing their accounts from multiple points as well as mobile devices, very impractical. From my understanding (I have recently heard), 2FA is not possible for some reason, but there must be other ways that can be used to protect an account even in the event of a lost key. The problem is that mass adoption means many people coming onto the platform who are a lot less security conscience than the average crypto enthusiast and on an immutable blockchain, the number of stolen and dead accounts is going to grow rapidly. It is going to be a tough sell to keep explaining why we can do nothing about theft and we offer no real preventative protection against it for the *average* user. There is a high learning curve here already but is it wise to have the idea of security and watch out for bad actors the first lesson learned coming into a community? If the experienced struggle with this, what hope do the newbies have? Not everyone should have to learn the hard way when it comes to account security and their should be some clear advice and solutions available that even the most basic user can understand considering this is a global community. I am unsure what is in the pipeline for security measures but in my opinion, a lot more needs to be developed to both simplify account management and complicate account theft before a million more people come I and lose their keys to a phishing attack in their first week and have their account turned into one of the soldiers in a bot army. Online security is a difficult area because often it requires some level of centralisation which becomes a weak and contentious point in a decentralised community. There is some kind of *lesser of two evils* concept at play but I am unsure which is the larger evil of the two. Until something is in place though, everyone has to remain on guard at all times and of something seems out of place like a login screen, it probably is it of place and should be treated with extreme caution. There are always going to be bad actors on Steem and in the world and this is why having a healthy and supportive community inherently provides some measure of security to protect its members. *All for one, one for all.* What are your thoughts on security on Steem and do you have any good advice or trusted tools to maintain security across devices? Taraz [ a Steem original ] <sub>(posted from phone)</sub>
author | tarazkp |
---|---|
permlink | security-watch-out-this-is-steem |
category | security |
json_metadata | {"tags":["security","steem","phishing","community","future"],"users":["surfermarly","arcange"],"image":["https://cdn.steemitimages.com/DQma2khkAgSKrQ4YLn4So48kkRGn8eoaiiAY5GuMVcJuxnn/20180918_204902.jpg"],"links":["https://steemit.com/steemit/@arcange/phishing-attempts-are-running-and-use-fake-comments-with-images"],"app":"steemit/0.1","format":"markdown"} |
created | 2018-09-18 18:43:39 |
last_update | 2018-09-19 08:15:54 |
depth | 0 |
children | 42 |
last_payout | 2018-09-25 18:43:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 21.899 HBD |
curator_payout_value | 6.496 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 4,266 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,608,424 |
net_rshares | 22,103,783,919,681 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
berniesanders | 0 | 4,826,195,747 | 0.75% | ||
pharesim | 0 | 10,924,982,758,004 | 100% | ||
nextgencrypto | 0 | 1,244,089,139 | 0.75% | ||
daan | 0 | 514,488,160 | 1% | ||
arcange | 0 | 31,955,103,905 | 5% | ||
raphaelle | 0 | 2,896,161,904 | 5% | ||
akipponn | 0 | 13,188,044,175 | 100% | ||
surfermarly | 0 | 35,110,063,578 | 100% | ||
elamental | 0 | 265,030,176 | 1% | ||
anarcho-andrei | 0 | 749,530,122 | 1.5% | ||
mattclarke | 0 | 141,197,479,893 | 20% | ||
thecyclist | 0 | 11,810,205,186 | 0.75% | ||
abh12345 | 0 | 88,470,517,488 | 10% | ||
votehumanity | 0 | 175,365,210 | 0.5% | ||
nelyp | 0 | 8,685,195,097 | 20% | ||
largelyuseless | 0 | 6,011,152,682 | 100% | ||
clayboyn | 0 | 4,532,801,611 | 5% | ||
cardinalkennedy | 0 | 545,422,589 | 20% | ||
nonameslefttouse | 0 | 462,002,672,648 | 50% | ||
engagement | 0 | 416,530,131 | 0.75% | ||
v4vapid | 0 | 3,899,234,277,663 | 29% | ||
iflagtrash | 0 | 155,526,314 | 0.75% | ||
tarazkp | 0 | 669,267,539,077 | 100% | ||
markkujantunen | 0 | 30,158,644,228 | 44% | ||
randomthoughts | 0 | 2,908,817,445 | 0.75% | ||
bart2305 | 0 | 4,640,269,320 | 3% | ||
anomadsoul | 0 | 2,058,304,938,353 | 20% | ||
pipurilla | 0 | 5,413,312,961 | 12% | ||
enjoywithtroy | 0 | 25,314,573,387 | 37% | ||
momogrow | 0 | 1,092,543,573 | 2.5% | ||
gohba.handcrafts | 0 | 1,397,159,705 | 5% | ||
isaria | 0 | 13,087,016,994 | 5% | ||
ladyrebecca | 0 | 41,765,124,884 | 100% | ||
galenkp | 0 | 47,496,895,618 | 100% | ||
crimsonclad | 0 | 29,968,515,744 | 10% | ||
teamaustralia | 0 | 2,196,391,169 | 3% | ||
centerlink | 0 | 143,299,928,870 | 20% | ||
jonmagnusson | 0 | 252,721,780 | 0.5% | ||
jayna | 0 | 381,747,244 | 0.75% | ||
thedelegator | 0 | 1,394,734,797 | 0.75% | ||
toofasteddie | 0 | 31,467,370,771 | 31% | ||
amymya | 0 | 210,431,601 | 0.2% | ||
redrica | 0 | 337,323,925 | 1.1% | ||
avesa | 0 | 278,301,421 | 0.33% | ||
minismallholding | 0 | 3,501,122,848 | 10% | ||
djlethalskillz | 0 | 1,327,248,051 | 2% | ||
kiriatjrb | 0 | 77,531,439 | 5% | ||
trevorpetrie | 0 | 801,716,537 | 5% | ||
torico | 0 | 335,356,211 | 0.4% | ||
diantbi | 0 | 1,428,127,519 | 10% | ||
sorin.cristescu | 0 | 78,947,317,709 | 50% | ||
carrieallen | 0 | 3,977,551,518 | 10% | ||
melavie | 0 | 131,603,418 | 1% | ||
infamousit | 0 | 4,493,474,669 | 25% | ||
gotmeens | 0 | 21,219,842,416 | 100% | ||
art-mess | 0 | 76,276,887 | 2.5% | ||
castleberry | 0 | 21,872,109,712 | 100% | ||
ngc | 0 | 151,195,007,112 | 0.75% | ||
rogeviolinista | 0 | 89,864,698 | 5% | ||
fknmayhem | 0 | 26,671,149,089 | 70% | ||
socent | 0 | 495,709,807 | 15% | ||
eonwarped | 0 | 2,755,589,084 | 1% | ||
karolisp | 0 | 112,720,484 | 1% | ||
not-a-bird | 0 | 7,923,483,811 | 50% | ||
pechichemena | 0 | 218,148,745 | 1% | ||
evilest-fiend | 0 | 3,464,715,083 | 100% | ||
steemobserver | 0 | 147,643,574 | 59.5% | ||
helpie | 0 | 58,443,742,600 | 5% | ||
markaustin | 0 | 211,344,918 | 5% | ||
luisferchav | 0 | 215,278,107 | 2.5% | ||
not-a-cat | 0 | 1,436,906,557 | 100% | ||
soulturtle | 0 | 134,139,048 | 1% | ||
mountainjewel | 0 | 273,919,347 | 0.5% | ||
notoriousrebel | 0 | 481,228,684 | 100% | ||
carpedimus | 0 | 85,131,994 | 2.5% | ||
abdulqayyum9585 | 0 | 483,001,893 | 100% | ||
rhmi90 | 0 | 188,487,292 | 5% | ||
sixdorks | 0 | 421,422,239 | 52.5% | ||
fieryfootprints | 0 | 967,407,940 | 100% | ||
grizzle | 0 | 197,524,273 | 1% | ||
heajin | 0 | 104,582,877 | 20% | ||
hazem91 | 0 | 173,048,285 | 1.25% | ||
verhp11 | 0 | 178,596,853 | 0.5% | ||
atomcollector | 0 | 963,837,499 | 3% | ||
alexdory | 0 | 56,616,721,025 | 100% | ||
kryptoe | 0 | 129,716,711 | 0.33% | ||
benleemusic | 0 | 12,320,895,878 | 5% | ||
eugenekul | 0 | 3,771,444,362 | 100% | ||
jbrrd | 0 | 158,789,131 | 11% | ||
suomibotti | 0 | 60,019,771,416 | 25% | ||
mindtrap | 0 | 12,964,662,737 | 20% | ||
wandairawan | 0 | 146,305,785 | 100% | ||
spawnband | 0 | 97,179,976 | 1% | ||
foxyspirit | 0 | 218,548,540 | 1% | ||
grayarty | 0 | 96,307,101 | 5% | ||
theturtleproject | 0 | 198,548,966 | 5% | ||
hlezama | 0 | 1,371,141,437 | 100% | ||
rognel2904 | 0 | 60,735,455 | 10% | ||
derangedvisions | 0 | 654,002,671 | 1% | ||
wolfhart | 0 | 25,079,587,701 | 50% | ||
blessed-girl | 0 | 2,481,379,567 | 100% | ||
lordbutterfly | 0 | 2,571,709,826 | 10% | ||
veckinon | 0 | 150,041,664 | 2.5% | ||
archaimusic | 0 | 258,640,633 | 10% | ||
musicvoter | 0 | 3,156,041,588 | 1% | ||
thexreposts | 0 | 211,650,782 | 10% | ||
educatie | 0 | 208,505,947 | 100% | ||
musicvoter2 | 0 | 147,347,334 | 10% | ||
cryptoandcoffee | 0 | 13,041,279,157 | 40% | ||
insaneworks | 0 | 1,777,611,928 | 100% | ||
ghost2 | 0 | 465,011,870 | 100% | ||
sp33dygonzales | 0 | 172,764,687 | 50% | ||
medicnet | 0 | 602,358,050 | 100% | ||
communityisyou | 0 | 602,358,050 | 100% | ||
lordofreward | 0 | 237,940,582 | 1.5% | ||
honshu | 0 | 623,693,236 | 100% | ||
blewitt | 0 | 9,400,330,830 | 4% | ||
dinoromanelli | 0 | 87,031,260 | 1% | ||
mrart | 0 | 65,625,045 | 10% | ||
tashidelek | 0 | 1,917,550,888,588 | 100% | ||
lillywilton | 0 | 1,688,096,795 | 20% | ||
jk6276 | 0 | 2,786,066,510 | 50% | ||
sbi7 | 0 | 5,627,738,175 | 3% | ||
filletsslither | 0 | 561,544,121 | 100% | ||
steemcontesting | 0 | 596,369,814 | 100% | ||
emsteemians | 0 | 524,625,208 | 10% | ||
donkeyslayer | 0 | 3,738,586,530 | 100% | ||
rodneysreviews | 0 | 3,042,875,550 | 100% | ||
hornetmusic | 0 | 172,141,997 | 50% | ||
fulltimebot45 | 0 | 122,949,679,782 | 100% | ||
truthbot | 0 | 10,137,304,069 | 100% | ||
fulltimebot65 | 0 | 122,571,972,250 | 100% | ||
fulltimebot68 | 0 | 122,608,344,694 | 100% | ||
fulltimebot69 | 0 | 122,616,329,956 | 100% | ||
steem-ua | 0 | 305,735,632,770 | 1.2% | ||
lovepreet2511 | 0 | 1,560,670,031 | 100% | ||
manoldonchev | 0 | 627,929,927 | 100% | ||
steemitbuzz | 0 | 90,706,261 | 50% | ||
hdu | 0 | 221,504,678 | 2% | ||
curbot | 0 | 1,516,873,503 | 5% | ||
spotlit | 0 | 260,208,783 | 100% | ||
prince23 | 0 | 606,323,645 | 100% |
We have to keep an eye out for everyone as it happens. I wish there was some other barrier of security that could be found. I know the power down takes 13 weeks but when Steem rockets this place would be like hitting a bank. It will become more serious than a few thousand dollars as we are talking in some cases millions.
author | cryptoandcoffee |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t185218697z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 18:52:21 |
last_update | 2018-09-18 18:52:21 |
depth | 1 |
children | 3 |
last_payout | 2018-09-25 18:52:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 322 |
author_reputation | 3,573,385,714,783,742 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,608,952 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
people can have Steem sitting in their wallet liquid too and sometimes, that is quite a lot. I am not sure what solutions are available but even a simple secondary pin with 3 attempts might be enough for most cases. Re-login would need master and come with an additional warning that the pin was inputted wrongly and to change the keys if it wasn't you.
author | tarazkp |
---|---|
permlink | re-cryptoandcoffee-re-tarazkp-security-watch-out-this-is-steem-20180918t185809230z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 18:58:03 |
last_update | 2018-09-18 18:58:03 |
depth | 2 |
children | 2 |
last_payout | 2018-09-25 18:58:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.020 HBD |
curator_payout_value | 0.003 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 353 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,609,278 |
net_rshares | 21,133,424,463 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
cryptoandcoffee | 0 | 10,392,269,328 | 32% | ||
milky-concrete | 0 | 10,741,155,135 | 19.35% |
Just don't understand. If you are not going to power up then stick it into savings. It doesn't matter if it is going to take 3 days to get it out, better safe than sorry.
author | cryptoandcoffee |
---|---|
permlink | re-tarazkp-re-cryptoandcoffee-re-tarazkp-security-watch-out-this-is-steem-20180918t191921862z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:19:24 |
last_update | 2018-09-18 19:19:24 |
depth | 3 |
children | 1 |
last_payout | 2018-09-25 19:19:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 170 |
author_reputation | 3,573,385,714,783,742 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,610,640 |
net_rshares | 0 |
People are despicable. Thanks for the heads up, I really am taking it a lot more seriously now
author | empress-eremmy |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t215950565z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 22:00:09 |
last_update | 2018-09-18 22:00:09 |
depth | 1 |
children | 0 |
last_payout | 2018-09-25 22:00:09 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 94 |
author_reputation | 537,410,962,648,252 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,620,129 |
net_rshares | 28,697,302,520 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,697,302,520 | 4% |
People are despicable. Thanks for the heads up, I really am taking it a lot more seriously now
author | empress-eremmy |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t220126443z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 22:01:39 |
last_update | 2018-09-18 22:01:39 |
depth | 1 |
children | 1 |
last_payout | 2018-09-25 22:01:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.003 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 94 |
author_reputation | 537,410,962,648,252 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,620,228 |
net_rshares | 28,611,815,084 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,611,815,084 | 4% |
>People are despicable. the "benefits" of having value on a platform... ;)
author | tarazkp |
---|---|
permlink | re-empress-eremmy-re-tarazkp-security-watch-out-this-is-steem-20180918t221348553z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 22:13:39 |
last_update | 2018-09-18 22:13:39 |
depth | 2 |
children | 0 |
last_payout | 2018-09-25 22:13:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 75 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,620,898 |
net_rshares | 0 |
I feel so sorry for @surfermarly in the attack. In a separate incident @kryptocoin got hacked as you can read about [here](https://steemit.com/familyprotection/@kryptocoin/hacked-when-you-get-pushed-out-of-your-own-house-by-an-impostor). Many months ago I was scamed 663 SBD by some Romnians. in a phising. One must be VERY careful. I learned the importance of not using your master key. Folks need to be educated about this. Decentralization is like the wild west of the internet. LoL Thanks my friend.
author | enjoywithtroy |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t192623188z |
category | security |
json_metadata | {"tags":["security"],"users":["surfermarly","kryptocoin"],"links":["https://steemit.com/familyprotection/@kryptocoin/hacked-when-you-get-pushed-out-of-your-own-house-by-an-impostor"],"app":"steemit/0.1"} |
created | 2018-09-18 19:27:57 |
last_update | 2018-09-18 19:27:57 |
depth | 1 |
children | 2 |
last_payout | 2018-09-25 19:27:57 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 512 |
author_reputation | 142,851,883,439,160 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 0 |
post_id | 71,611,144 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
>Decentralization is like the wild west of the internet Don't trust anyone ever.
author | tarazkp |
---|---|
permlink | re-enjoywithtroy-re-tarazkp-security-watch-out-this-is-steem-20180918t193226760z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:32:18 |
last_update | 2018-09-18 19:32:18 |
depth | 2 |
children | 1 |
last_payout | 2018-09-25 19:32:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 81 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,380 |
net_rshares | 0 |
> Don't trust anyone ever. **Unless...** you want to consult with *experts* who **really know. };)** 
author | por500bolos |
---|---|
permlink | re-tarazkp-re-enjoywithtroy-re-tarazkp-security-watch-out-this-is-steem-20180919t014311610z |
category | security |
json_metadata | {"tags":["security"],"image":["https://cdn.steemitimages.com/DQmcwjwoMtbtfFsDaKEH6BN2JhkM8T2YoH1iAuGjjJrtupM/Security_Check.jpg"],"app":"steemit/0.1"} |
created | 2018-09-19 01:43:12 |
last_update | 2018-09-19 01:43:12 |
depth | 3 |
children | 0 |
last_payout | 2018-09-26 01:43:12 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.029 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 222 |
author_reputation | 14,975,733,879,671 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,632,084 |
net_rshares | 28,697,302,520 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,697,302,520 | 4% |
I was going to ask if for the security aspect of Steemit is discussed during the Steem gatherings (fests?). If there were talents capable of developing something as complex as blockchain, my guess is there gotta be equal or better talents to counter attack and protect this thing. I know nothing about tech and i don't think with the meager resources we have at hand here i'll be able to learn or have access to any kind of security measures, unless the paltform develops methods to protect everybody. Yesterday, precisely i was asked by an alleged member of the cervantes group to participate on an alleged program of delegation (i had been allegedly chosen to have a chance). He sent me the link to a @cervantes post showing the first month's winner and all. It so happens that that user is not @pgarcgo #0325, his discord number was different. I did not know @cervantes had already issued a warning or something like that. I wonder if that "user" has been tracked down and blocked or something.
author | hlezama |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t193601972z |
category | security |
json_metadata | {"tags":["security"],"users":["cervantes","pgarcgo"],"app":"steemit/0.1"} |
created | 2018-09-18 19:36:03 |
last_update | 2018-09-18 19:37:36 |
depth | 1 |
children | 2 |
last_payout | 2018-09-25 19:36:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 997 |
author_reputation | 265,529,475,623,172 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,641 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
>I know nothing about tech and i don't think with the meager resources we have at hand here i'll be able to learn or have access to any kind of security measures, - never use your master key unless changing your other keys. Keep it offline. - only log in with your posting key - only use your active key for transfers - never give them to anyone.
author | tarazkp |
---|---|
permlink | re-hlezama-re-tarazkp-security-watch-out-this-is-steem-20180918t194012050z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:40:03 |
last_update | 2018-09-18 19:40:03 |
depth | 2 |
children | 1 |
last_payout | 2018-09-25 19:40:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 349 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,872 |
net_rshares | 0 |
Thanks, @tarazkp
author | hlezama |
---|---|
permlink | re-tarazkp-re-hlezama-re-tarazkp-security-watch-out-this-is-steem-20180918t195138663z |
category | security |
json_metadata | {"tags":["security"],"users":["tarazkp"],"app":"steemit/0.1"} |
created | 2018-09-18 19:51:39 |
last_update | 2018-09-18 19:51:39 |
depth | 3 |
children | 0 |
last_payout | 2018-09-25 19:51:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 16 |
author_reputation | 265,529,475,623,172 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,612,572 |
net_rshares | 0 |
A good thing you brought up this story - been sort of busy and I didn't look into details earlier - using a name with great rep that's pretty smart... The shock of seeing such a message from someone important could easily make you ignore the risks you are normally aware. As for the masses hopefully joining Steemit - security would definitely be a problem... if people keep losing their keys, word would spread the site is not safe.. which wouldn't be good!
author | ladyrebecca |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t194302096z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:43:24 |
last_update | 2018-09-18 19:43:24 |
depth | 1 |
children | 1 |
last_payout | 2018-09-25 19:43:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 458 |
author_reputation | 122,127,717,116,461 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,612,066 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
The shock of seeing such a message from someone important could easily make you ignore the risks you are normally aware. It is a type of greed. I am not saying in this particular case but it plays on the trigger. Same in chats when *"Vhales"* promise votes etc for a few SBD transferred to blocktrades. The want for it to be real overpowers the rational mind.
author | tarazkp |
---|---|
permlink | re-ladyrebecca-re-tarazkp-security-watch-out-this-is-steem-20180918t194729701z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:47:21 |
last_update | 2018-09-18 19:47:21 |
depth | 2 |
children | 0 |
last_payout | 2018-09-25 19:47:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 360 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,612,314 |
net_rshares | 0 |
We must protect our key to avoid checkmate friends, since there are many cheats in digital questions. My greetings, @tarazkp.
author | lauram |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t185955353z |
category | security |
json_metadata | {"tags":["security"],"users":["tarazkp"],"app":"steemit/0.1"} |
created | 2018-09-18 18:59:51 |
last_update | 2018-09-18 18:59:51 |
depth | 1 |
children | 0 |
last_payout | 2018-09-25 18:59:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 125 |
author_reputation | 1,921,696,906,491 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,609,397 |
net_rshares | 0 |
I don't share my key with anyone but I am afraid about it is there any way we can keep our account safe
author | lovepreet2511 |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180919t065811467z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-19 06:58:12 |
last_update | 2018-09-19 06:58:12 |
depth | 1 |
children | 0 |
last_payout | 2018-09-26 06:58:12 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 103 |
author_reputation | 1,149,150,491,604 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,650,814 |
net_rshares | 0 |
Actually a few good ideas to prevent abuse are in place on steemit and I like them so much. I haven't yet reached a point to try and withdraw any funds but I like the time limitations - the SP withdrawal limit of 1/13 per day makes me feel much more secure than in a case I witnessed a few years ago. My third person view: In 2008 my roommates started digging bitcoins. It required about 500 Euro only for a good enough machine. I was about to invest in one. My roomies had already acquired - in a matter of weeks - a few bitcoins per person which now would be worth a small fortune. One day the system got hacked, their few bitcoins drained immediately and although it took a short time to get the system running again, few people had the courage to dedicate resources again. I didn't even start. I've been stolen from in real life - a few bikes, guitars, thing like these. Still it felt very bad. Not because of the money but because of the unexpected insult to my hard work related beliefs.
author | manoldonchev |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t192706558z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:27:03 |
last_update | 2018-09-18 19:27:03 |
depth | 1 |
children | 2 |
last_payout | 2018-09-25 19:27:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 996 |
author_reputation | 292,116,483,961,241 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,100 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
>the SP withdrawal limit of 1/13 per day makes me feel much more secure than in a case I witnessed a few years ago. per *week* >I've been stolen from in real life - a few bikes, guitars, thing like these. Still it felt very bad. Not because of the money but because of the unexpected insult to my hard work related beliefs. It is a personal violation and intentional which makes it worse.
author | tarazkp |
---|---|
permlink | re-manoldonchev-re-tarazkp-security-watch-out-this-is-steem-20180918t193138250z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:31:30 |
last_update | 2018-09-18 19:31:30 |
depth | 2 |
children | 1 |
last_payout | 2018-09-25 19:31:33 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 391 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,342 |
net_rshares | 0 |
Yup, exactly that - the personal violation. It stays the same even online. I guess I should learn to use the alternative keys and not the master. Thank you very much for bringing up the issue :) My wish on the matter of decentralization is for the community to find enough strength and produce enough ideas so that it proves decentralized can still be secure. That would be so much more than just a social network benefit.
author | manoldonchev |
---|---|
permlink | re-tarazkp-re-manoldonchev-re-tarazkp-security-watch-out-this-is-steem-20180918t200542238z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 20:05:39 |
last_update | 2018-09-18 20:05:39 |
depth | 3 |
children | 0 |
last_payout | 2018-09-25 20:05:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.001 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 423 |
author_reputation | 292,116,483,961,241 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,613,444 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
Good news on that front actually. There's a browser extension almost released, (commissioned by a couple of the witnesses). It holds your keys in your browser and just sends a token through the net. Your keys never actually leave your browser. Its like metamask for Ethereum. I've been using it for a week or so and it's really top notch. Not sure when official launch will be, but I'd say very soon.
author | mattclarke |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180918t190027384z |
category | security |
json_metadata | {"tags":["security"],"community":"steempeak","app":"steempeak"} |
created | 2018-09-18 19:00:30 |
last_update | 2018-09-18 19:00:30 |
depth | 1 |
children | 5 |
last_payout | 2018-09-25 19:00:30 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.256 HBD |
curator_payout_value | 0.046 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 400 |
author_reputation | 127,126,990,436,054 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,609,444 |
net_rshares | 259,704,242,833 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tobixen | 0 | 161,338,471,454 | 62% | ||
abh12345 | 0 | 31,224,888,525 | 3% | ||
tarazkp | 0 | 62,922,589,144 | 9% | ||
minismallholding | 0 | 3,501,122,848 | 10% | ||
gansekirock | 0 | 717,170,862 | 100% |
That s awesome, by any chance does it work on mobile?
author | tarazkp |
---|---|
permlink | re-mattclarke-re-tarazkp-security-watch-out-this-is-steem-20180918t190408439z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 19:04:00 |
last_update | 2018-09-18 19:04:00 |
depth | 2 |
children | 4 |
last_payout | 2018-09-25 19:04:00 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 53 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,609,648 |
net_rshares | 0 |
I haven't tried, tbh. I use the Brave browser on my mobile, and I don't imagine it's compatible yet. It works great in chrome on my desktop though. Not sure about steemit.com, but I know steempeak.com and steemmonsters.com are testing it out. I've used it on both and it's heaps quicker and simpler than steemconnect.
author | mattclarke |
---|---|
permlink | re-tarazkp-re-mattclarke-re-tarazkp-security-watch-out-this-is-steem-20180918t192919083z |
category | security |
json_metadata | {"tags":["security"],"community":"steempeak","app":"steempeak"} |
created | 2018-09-18 19:29:21 |
last_update | 2018-09-18 19:31:00 |
depth | 3 |
children | 3 |
last_payout | 2018-09-25 19:29:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.001 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 318 |
author_reputation | 127,126,990,436,054 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,611,219 |
net_rshares | 28,601,176,883 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,601,176,883 | 4% |
I notice that links that take you away from Steemit have a little symbol to let you know. I wonder if this was hidden, somehow, in this case. Perhaps this could be extended to a warning when you click on it to say you are being diverted to a different site. Admittedly, it could get annoying if you click on links a lot, though.
author | minismallholding |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180919t133508924z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-19 13:35:06 |
last_update | 2018-09-20 00:51:30 |
depth | 1 |
children | 2 |
last_payout | 2018-09-26 13:35:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.022 HBD |
curator_payout_value | 0.007 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 328 |
author_reputation | 296,511,339,642,720 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,676,497 |
net_rshares | 22,916,520,063 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 22,916,520,063 | 3% |
I think it was an image cut and paste from a real comment. Never use your master.
author | tarazkp |
---|---|
permlink | re-minismallholding-re-tarazkp-security-watch-out-this-is-steem-20180919t180258366z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-19 18:02:51 |
last_update | 2018-09-19 18:02:51 |
depth | 2 |
children | 1 |
last_payout | 2018-09-26 18:02:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 81 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,696,294 |
net_rshares | 0 |
Even images have the little symbol in the corner. They must have been pretty clever to get around that somehow. Yes, most certainly never user your master and really check the address bar. You are so right, though, it's not going to help with onboarding in the long run. Even the pass keys are off putting to many. It needs to be a bit simpler and safer.
author | minismallholding |
---|---|
permlink | re-tarazkp-re-minismallholding-re-tarazkp-security-watch-out-this-is-steem-20180920t005504267z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 00:55:00 |
last_update | 2018-09-20 00:55:00 |
depth | 3 |
children | 0 |
last_payout | 2018-09-27 00:55:00 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 355 |
author_reputation | 296,511,339,642,720 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,719,803 |
net_rshares | 0 |
#### Hi @tarazkp! Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation! Your **UA** account score is currently 6.118 which ranks you at **#253** across all Steem accounts. Your rank has improved 3 places in the last three days (old rank 256). In our last Algorithmic Curation Round, consisting of 516 contributions, your post is ranked at **#17**. ##### Evaluation of your UA score: * You've built up a nice network. * The readers appreciate your great work! * Great user engagement! You rock! **Feel free to join our [@steem-ua Discord server](https://discord.gg/KpBNYGz)**
author | steem-ua |
---|---|
permlink | re-security-watch-out-this-is-steem-20180921t150008z |
category | security |
json_metadata | "{"app": "beem/0.19.54"}" |
created | 2018-09-21 15:00:09 |
last_update | 2018-09-21 15:00:09 |
depth | 1 |
children | 0 |
last_payout | 2018-09-28 15:00:09 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.029 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 628 |
author_reputation | 23,214,230,978,060 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,864,577 |
net_rshares | 28,724,328,561 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,724,328,561 | 4% |
**Thanks a lot for bringing this up!** We can't talk often enough about security measures and educate the community. I did a huge mistake and stepped into a really uncool trap - which then taught me for life, so I'm glad to share my experience with and warn others now. *Appreciated & resteemed*
author | surfermarly |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180920t190944882z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 19:09:48 |
last_update | 2018-09-20 19:09:48 |
depth | 1 |
children | 5 |
last_payout | 2018-09-27 19:09:48 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.029 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 296 |
author_reputation | 318,958,646,866,746 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,792,563 |
net_rshares | 28,697,302,520 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,697,302,520 | 4% |
It is a challenge because compared to 'normal sites', there is more complexity here and not a great deal of clear communication. Combine that with some clever scammers and it is unfortunately going to be more and more of an issue moving forward with mainstreaming.
author | tarazkp |
---|---|
permlink | re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t191227063z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 19:12:21 |
last_update | 2018-09-20 19:12:21 |
depth | 2 |
children | 1 |
last_payout | 2018-09-27 19:12:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.039 HBD |
curator_payout_value | 0.012 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 264 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,792,729 |
net_rshares | 39,611,353,781 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
surfermarly | 0 | 39,611,353,781 | 100% |
Absolutely, only having a serious of different keys (compared to one password you usually have on other social media sites) makes it incredibly complex. Sometimes it's not even about not being informed, but being distracted - like it happened to me twice. A couple of weeks back, I accidentally introduced my active key into the *memo* field of the smartsteem promotion service. At that point in time, there was no alert implemented yet, that informed you when you accidentally typed something into the field that looked like a key. I lost 18 SBD which was not much, but still a lesson. As a positive takeaway, the website was updated and now people are warned when introducing a key into the wrong field (like it was already implemented on steemit.com before). The second time (as you mentioned here) I was provided with a phishing link that was wearing such a good make-up that already 850 other users had been fallen for it (as I learned later on from a developer). Eight hundred fifty people! Now the no. 1 rule is surely to NEVER use the wrong key. That can prevent us from a lot of trouble. Total security doesn't exist when human beings are involved - as in real life so online. However, I feel that there's a big lack of education and we should start a whole campaign to better inform those who join us. Btw I was desperately trying to find some information in the Steemit FAQ on how to safely STORE keys. It's just said that they should be stored safely / offline, but a non-crypto person would never understand at first glance what that actually means... Again, thanks for bringing this up! We need more of it :-)
author | surfermarly |
---|---|
permlink | re-tarazkp-re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180921t064520864z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-21 06:45:24 |
last_update | 2018-09-21 06:47:36 |
depth | 3 |
children | 0 |
last_payout | 2018-09-28 06:45:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,630 |
author_reputation | 318,958,646,866,746 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,831,758 |
net_rshares | 0 |
I also had a close run a couple of years ago, with Localbitcoins. I'm considering myself as an expert, so I found it quite embarrassing, but it sort of proves the point that even experienced users may fall for phishing. I got a phishing email, opened it on my mobile. Now, on my regular desktop email client (mutt), I can quite easily detect phishing-attempts, but on the mobile details like the senders email address and what email server it came from was hidden. In addition I was trying to pay attention to a real life talk, and in addition I was drinking beer and not being completely sober ... so I followed a link urging me to log into my localbitcoins account. So the phisherman got my password. Luckily Localbitcoins have an extra measure of security by cookies, they don't allow logins from a new browser without the account holder first confirming it by email, so when I got a "confirm this login alert", I understood that I had been phished, didn't lose anything and could change my password simply.
author | tobixen |
---|---|
permlink | re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t200842179z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 20:08:42 |
last_update | 2018-09-20 20:08:42 |
depth | 2 |
children | 1 |
last_payout | 2018-09-27 20:08:42 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,016 |
author_reputation | 18,276,555,395,725 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,796,079 |
net_rshares | 0 |
Thanks for being so open @tobixen, and I'm grateful you mentioned that the experience can not protect us. Especially phishing links are quite elaborated nowadays, and a single second of distraction may drive you right into a big disaster. Steem users log-in themselves from different devices every day, and I'm pretty sure that this is one of the biggest security gaps. I have no keys on my phone anymore, but sometimes it's annoying that I can't upvote or comment posts while I'm on the move. It's hard to define a well working synergy of flexibility, efficiency and security. Probably we can't have them all.
author | surfermarly |
---|---|
permlink | re-tobixen-re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180921t070819284z |
category | security |
json_metadata | {"tags":["security"],"users":["tobixen"],"app":"steemit/0.1"} |
created | 2018-09-21 07:08:24 |
last_update | 2018-09-21 07:08:24 |
depth | 3 |
children | 0 |
last_payout | 2018-09-28 07:08:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 613 |
author_reputation | 318,958,646,866,746 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,833,019 |
net_rshares | 0 |
I also had a close run a couple of years ago, with Localbitcoins. I'm considering myself as an expert, so I found it quite embarrassing, but it sort of proves the point that even experienced users may fall for phishing. I got a phishing email, opened it on my mobile. Now, on my regular desktop email client (mutt), I can quite easily detect phishing-attempts, but on the mobile details like the senders email address and what email server it came from was hidden. In addition I was trying to pay attention to a real life talk, and in addition I was drinking beer and not being completely sober ... so I followed a link urging me to log into my localbitcoins account. So the phisherman got my password. Luckily Localbitcoins have an extra measure of security by cookies, they don't allow logins from a new browser without the account holder first confirming it by email, so when I got a "confirm this login alert", I understood that I had been phished, didn't lose anything and could change my password simply.
author | tobixen |
---|---|
permlink | re-surfermarly-re-tarazkp-security-watch-out-this-is-steem-20180920t201103308z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 20:11:06 |
last_update | 2018-09-20 20:11:06 |
depth | 2 |
children | 0 |
last_payout | 2018-09-27 20:11:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 1,016 |
author_reputation | 18,276,555,395,725 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,796,222 |
net_rshares | 0 |
Sometimes this turns into a fear. I have nothing to be 'syphoned' currently but I wonder what will happen when I do. I can imagine how painful it is for someone who has gone through it. Posted using [Partiko Android](https://steemit.com/@partiko-android)
author | tezmel |
---|---|
permlink | tezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t210151883z |
category | security |
json_metadata | {"app":"partiko"} |
created | 2018-09-18 21:01:51 |
last_update | 2018-09-18 21:01:51 |
depth | 1 |
children | 2 |
last_payout | 2018-09-25 21:01:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.022 HBD |
curator_payout_value | 0.007 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 256 |
author_reputation | 111,344,076,038,127 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,616,607 |
net_rshares | 22,889,452,067 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 22,889,452,067 | 3% |
gotta stay frosty in the Steem jungle :)
author | tarazkp |
---|---|
permlink | re-tezmel-tezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t213755035z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-18 21:37:48 |
last_update | 2018-09-18 21:37:48 |
depth | 2 |
children | 1 |
last_payout | 2018-09-25 21:37:48 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 40 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,618,886 |
net_rshares | 0 |
So it seems! Sigh. Posted using [Partiko Android](https://steemit.com/@partiko-android)
author | tezmel |
---|---|
permlink | tezmel-re-tarazkp-re-tezmel-tezmel-re-tarazkp-security-watch-out-this-is-steem-20180918t223239911z |
category | security |
json_metadata | {"app":"partiko"} |
created | 2018-09-18 22:32:39 |
last_update | 2018-09-18 22:32:39 |
depth | 3 |
children | 0 |
last_payout | 2018-09-25 22:32:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.028 HBD |
curator_payout_value | 0.007 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 88 |
author_reputation | 111,344,076,038,127 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,621,817 |
net_rshares | 28,611,815,084 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,611,815,084 | 4% |
Steem does have some tools in the toolbox, like the "saving account", the fact that it takes long time to "power down", plus the account recovery feature
author | tobixen |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180920t200333415z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 20:03:33 |
last_update | 2018-09-20 20:03:33 |
depth | 1 |
children | 0 |
last_payout | 2018-09-27 20:03:33 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 153 |
author_reputation | 18,276,555,395,725 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,795,775 |
net_rshares | 0 |
USE YOUR POSTING KEY for everyday use!
author | v4vapid |
---|---|
permlink | re-tarazkp-security-watch-out-this-is-steem-20180919t015619773z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-19 01:56:21 |
last_update | 2018-09-19 01:56:21 |
depth | 1 |
children | 1 |
last_payout | 2018-09-26 01:56:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.029 HBD |
curator_payout_value | 0.008 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 38 |
author_reputation | 227,173,587,450,152 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,632,841 |
net_rshares | 28,697,302,520 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
tarazkp | 0 | 28,697,302,520 | 4% |
Indeed. it is amazing how many use their master for *convenience.*
author | tarazkp |
---|---|
permlink | re-v4vapid-re-tarazkp-security-watch-out-this-is-steem-20180920t190953276z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2018-09-20 19:09:48 |
last_update | 2018-09-20 19:09:48 |
depth | 2 |
children | 0 |
last_payout | 2018-09-27 19:09:48 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 66 |
author_reputation | 5,837,594,903,387,606 |
root_title | "Security: Watch out, this is Steem" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 71,792,566 |
net_rshares | 0 |