create account

On Sharing Keys and Passwords with SteemConnect: How Safe Is It? by technerd888

View this thread on: hive.blogpeakd.comecency.com
· @technerd888 ·
$29.13
On Sharing Keys and Passwords with SteemConnect: How Safe Is It?
While "steem surfing" (Ok, I just coined this term on my own for lack of an official terminology), I managed to encounter some sites where they redirect and require you to sign-in via SteemConnect before proceeding.   

For those who don't know, "SteemConnect is the ideal solution for making it easy and safe for users to sign in to 3rd party Steem applications and for developers to build and scale these applications." (Source: https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain).  This indeed sounds like a great platform.  Instead of having to share your Steemit keys with all sorts of different third party apps, SteemConnect acts as a common, familiar and comfortable middleman that handles all your authentication needs with these apps.

There is only one hurdle for me -- SteemConnect will sometimes ask for your active or owner key, or even your master password.  

<center>![Screen Shot 2018-02-05 at 6.12.13 AM.png](https://steemitimages.com/DQmNWgYbJhGUH4hNecxbe6zsLMGCLkRMGAZiwWe9AkHDiTP/Screen%20Shot%202018-02-05%20at%206.12.13%20AM.png)</center>

This instantly blares a warning signal in my mind : "Can we trust SteemConnect with our keys and passwords?"  I'm sure some of us have also noticed the warning from the Steemit site whenever we check our wallets:

<center>![Screen Shot 2018-02-05 at 6.13.52 AM.png](https://steemitimages.com/DQmQ4kbCdBFPwWtiSXURYPU19QjYAE63Hqb8FbRZjNv32Eb/Screen%20Shot%202018-02-05%20at%206.13.52%20AM.png)</center>

So can we really trust SteemConnect with our keys and passwords?

In summarizing my research, I was able to gather the following three points,  which I believe others with the same concerns would appreciate:

1. **SteemConnect is actually an official partnership between Steemit Inc and the Busy team.**  We do trust our keys and password with Steemit, so to have the official backing and collaboration of the Steemit team themselves with the original developers of SteemConnect is certainly a confidence booster. Check out the post here: https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain

2. The article goes on to say that **"SteemConnect is a community project. That’s why it’s open source under MIT license, for anyone to use (and contribute to) as they see fit!"** This is another plus point for me.  No hidden codes, the entire code is available for everyone to use, study and contribute to.

3. And finally, I managed to also get a clarification from @Fabien, one of the founders of @Busy.org.  Here is his clear and concise reply: "With SteemConnect2 you need to grant @busy.app permission to post on your behalf, so the app busy can post for you. This operation require at least your active key when you authorize the app then you can login with you memo key or posting key. You can revoke @busy.app anytime using this link http://steemconnect.com/revoke/@busy.app
The active key is only used to make the operation in your browser then discarded, nothing stay or goes to the server."

After internalizing all my research, I'm quite reassured.  I hope this also adds valuable inputs to those who are worried about this particular concern.

As always, let me know your thoughts and feedback on this matter.  Have a great week ahead!
👍  , , , , , , , , , , , , , , , ,
properties (23)
authortechnerd888
permlinkon-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it
categorysteemconnect
json_metadata{"tags":["steemconnect","steemit","steem","security","busy"],"users":["fabien","busy.org","busy.app"],"image":["https://steemitimages.com/DQmNWgYbJhGUH4hNecxbe6zsLMGCLkRMGAZiwWe9AkHDiTP/Screen%20Shot%202018-02-05%20at%206.12.13%20AM.png","https://steemitimages.com/DQmQ4kbCdBFPwWtiSXURYPU19QjYAE63Hqb8FbRZjNv32Eb/Screen%20Shot%202018-02-05%20at%206.13.52%20AM.png"],"links":["https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain","http://steemconnect.com/revoke/@busy.app"],"app":"steemit/0.1","format":"markdown"}
created2018-02-05 11:31:45
last_update2018-02-05 11:31:45
depth0
children14
last_payout2018-02-12 11:31:45
cashout_time1969-12-31 23:59:59
total_payout_value21.860 HBD
curator_payout_value7.269 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,300
author_reputation5,061,271,852,330
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id35,123,632
net_rshares4,212,518,839,863
author_curate_reward""
vote details (17)
@cryptostyle ·
Deffinitely We can trust on it.I agreed with you...
properties (22)
authorcryptostyle
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180205t154711963z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-02-05 15:47:18
last_update2018-02-05 15:47:18
depth1
children1
last_payout2018-02-12 15:47:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length51
author_reputation740,830,204,600
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id35,175,020
net_rshares0
@technerd888 ·
Great to hear your affirmation. Cheers! :)
properties (22)
authortechnerd888
permlinkre-cryptostyle-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180206t133724466z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-02-06 13:37:27
last_update2018-02-06 13:37:27
depth2
children0
last_payout2018-02-13 13:37:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length42
author_reputation5,061,271,852,330
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id35,407,321
net_rshares0
@dickcastle ·
i cant login into steemconnect, is the password the same as my master key then?  im a little confused and its really aggravating me
properties (22)
authordickcastle
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190217t024956430z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2019-02-17 02:49:57
last_update2019-02-17 02:49:57
depth1
children0
last_payout2019-02-24 02:49:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length131
author_reputation807,410,408
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id79,981,965
net_rshares0
@fuzzyj ·
Thanks for this post, really helpful :)
properties (22)
authorfuzzyj
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190118t073534000z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2019-01-18 07:35:39
last_update2019-01-18 07:35:39
depth1
children0
last_payout2019-01-25 07:35:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length39
author_reputation430,509,323
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id78,541,357
net_rshares0
@monker ·
Getting an error when I  try to log in. Says not enough mana?
properties (22)
authormonker
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190421t075623538z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2019-04-21 07:56:24
last_update2019-04-21 07:56:24
depth1
children0
last_payout2019-04-28 07:56:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length61
author_reputation543,763,209,086
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id83,487,620
net_rshares0
@overunitydotcom ·
$0.03
But what, if http://steemconnect.com is ever hacked and manipulated to fish the Master passwords in this process ??
👍  
properties (23)
authoroverunitydotcom
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180329t184050508z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"links":["http://steemconnect.com"],"app":"steemit/0.1"}
created2018-03-29 18:40:51
last_update2018-03-29 18:40:51
depth1
children5
last_payout2018-04-05 18:40:51
cashout_time1969-12-31 23:59:59
total_payout_value0.031 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length115
author_reputation306,060,043,399
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id47,325,158
net_rshares10,836,080,013
author_curate_reward""
vote details (1)
@technerd888 ·
$0.14
Hi @overunitydotcom, I'm not an expert in security.  But I think getting hacked is certainly within the realm of possibility.  There are some things we can do to reduce this possibility.  First, make sure the steemconnect must be accessed via a secure HTTPS connection, so you'll need to make sure you see this on your browser:

<center>![Screen Shot 2018-03-30 at 6.43.28 AM.png](https://gateway.ipfs.io/ipfs/QmemxMCP4X8U1eQ3ofGFY6som99wDUsrtCJ4ELfaU6t3kK)</center>

Second, always use the Posting Key if all you're gonna be doing are upvoting, posting and commenting.  If you do need to transfer Steem or SBD, or grant an app access to your account, use the Active Key.  In short, never ever use your Owner Key -- reserve the owner key only for changing passwords.  

Third, if you have any SBD or Steem in your wallet, move them to Savings or Power Up to Steem Power.

These should minimize your risk exposure.  Hope this helps.
👍  , ,
properties (23)
authortechnerd888
permlinkre-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180330t105119676z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"community":"busy","app":"busy/2.4.0"}
created2018-03-30 10:51:30
last_update2018-03-30 10:51:30
depth2
children4
last_payout2018-04-06 10:51:30
cashout_time1969-12-31 23:59:59
total_payout_value0.106 HBD
curator_payout_value0.034 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length931
author_reputation5,061,271,852,330
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id47,434,420
net_rshares46,864,915,570
author_curate_reward""
vote details (3)
@overunitydotcom · (edited)
$0.11
Hmm, but steeemconnect wants to have your master key, not just your posting key... 
So who is running Steemconnect.com ?
They don´t even have an impressum ( about us) on their website... Why should I trust them with my master keys ???
👍  ,
properties (23)
authoroverunitydotcom
permlinkre-technerd888-re-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180420t180656226z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-04-20 18:07:00
last_update2018-04-20 18:07:21
depth3
children2
last_payout2018-04-27 18:07:00
cashout_time1969-12-31 23:59:59
total_payout_value0.104 HBD
curator_payout_value0.003 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length234
author_reputation306,060,043,399
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id51,168,768
net_rshares19,239,679,267
author_curate_reward""
vote details (2)
@overunitydotcom ·
$0.09
Where is then my Masterkey stored ? On the Steemconnect.com database or where ?
Who can access it ?
👍  , , ,
properties (23)
authoroverunitydotcom
permlinkre-technerd888-re-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180420t180849208z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-04-20 18:08:51
last_update2018-04-20 18:08:51
depth3
children0
last_payout2018-04-27 18:08:51
cashout_time1969-12-31 23:59:59
total_payout_value0.087 HBD
curator_payout_value0.003 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length99
author_reputation306,060,043,399
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id51,169,050
net_rshares15,933,743,548
author_curate_reward""
vote details (4)
@pozmu · (edited)
Informative post and comments, but I think it's generally a mess. Steemit should have this feature built-in, we shouldn't have to use 3rd party website. 

> They don't store the keys that you enter in steemconnect.

Ok, that's interesting, so where is it stored? In a cookie? I hope it's at least properly encrypted...

**Edit:** Maybe I was too harsh calling it a mess, we have to remember it's all build on top of blockchain.
properties (22)
authorpozmu
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180808t163555861z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-08-08 16:35:51
last_update2018-08-08 17:04:54
depth1
children0
last_payout2018-08-15 16:35:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length427
author_reputation1,193,834,520
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id67,545,053
net_rshares0
@rok-sivante ·
I’ve been using Steemconnect on Musing and dLike... however today upon trying to login, it doesn’t offer the option to click my usual account, but it starting from scratch asking for my username and key - which has never happened since I first input it months ago...

Wondering if this is anything to be concerned about, if there has been an app-wise reset, this is normal, etc...

you happen to know what's up?
👍  
properties (23)
authorrok-sivante
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190130t234141699z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2019-01-30 23:41:42
last_update2019-01-30 23:41:42
depth1
children0
last_payout2019-02-06 23:41:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length411
author_reputation664,589,362,019,250
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id79,186,019
net_rshares2,679,179,875
author_curate_reward""
vote details (1)
@yardne ·
thanks, i have had the same concerns, but now I am going to use steemconnect
properties (22)
authoryardne
permlinkre-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180605t203346748z
categorysteemconnect
json_metadata{"tags":["steemconnect"],"app":"steemit/0.1"}
created2018-06-05 20:33:48
last_update2018-06-05 20:33:48
depth1
children0
last_payout2018-06-12 20:33:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length76
author_reputation1,008,468,376,448
root_title"On Sharing Keys and Passwords with SteemConnect: How Safe Is It?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id59,426,322
net_rshares0