While "steem surfing" (Ok, I just coined this term on my own for lack of an official terminology), I managed to encounter some sites where they redirect and require you to sign-in via SteemConnect before proceeding. For those who don't know, "SteemConnect is the ideal solution for making it easy and safe for users to sign in to 3rd party Steem applications and for developers to build and scale these applications." (Source: https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain). This indeed sounds like a great platform. Instead of having to share your Steemit keys with all sorts of different third party apps, SteemConnect acts as a common, familiar and comfortable middleman that handles all your authentication needs with these apps. There is only one hurdle for me -- SteemConnect will sometimes ask for your active or owner key, or even your master password. <center></center> This instantly blares a warning signal in my mind : "Can we trust SteemConnect with our keys and passwords?" I'm sure some of us have also noticed the warning from the Steemit site whenever we check our wallets: <center></center> So can we really trust SteemConnect with our keys and passwords? In summarizing my research, I was able to gather the following three points, which I believe others with the same concerns would appreciate: 1. **SteemConnect is actually an official partnership between Steemit Inc and the Busy team.** We do trust our keys and password with Steemit, so to have the official backing and collaboration of the Steemit team themselves with the original developers of SteemConnect is certainly a confidence booster. Check out the post here: https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain 2. The article goes on to say that **"SteemConnect is a community project. That’s why it’s open source under MIT license, for anyone to use (and contribute to) as they see fit!"** This is another plus point for me. No hidden codes, the entire code is available for everyone to use, study and contribute to. 3. And finally, I managed to also get a clarification from @Fabien, one of the founders of @Busy.org. Here is his clear and concise reply: "With SteemConnect2 you need to grant @busy.app permission to post on your behalf, so the app busy can post for you. This operation require at least your active key when you authorize the app then you can login with you memo key or posting key. You can revoke @busy.app anytime using this link http://steemconnect.com/revoke/@busy.app The active key is only used to make the operation in your browser then discarded, nothing stay or goes to the server." After internalizing all my research, I'm quite reassured. I hope this also adds valuable inputs to those who are worried about this particular concern. As always, let me know your thoughts and feedback on this matter. Have a great week ahead!
author | technerd888 |
---|---|
permlink | on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it |
category | steemconnect |
json_metadata | {"tags":["steemconnect","steemit","steem","security","busy"],"users":["fabien","busy.org","busy.app"],"image":["https://steemitimages.com/DQmNWgYbJhGUH4hNecxbe6zsLMGCLkRMGAZiwWe9AkHDiTP/Screen%20Shot%202018-02-05%20at%206.12.13%20AM.png","https://steemitimages.com/DQmQ4kbCdBFPwWtiSXURYPU19QjYAE63Hqb8FbRZjNv32Eb/Screen%20Shot%202018-02-05%20at%206.13.52%20AM.png"],"links":["https://busy.org/@steemitblog/steemconnect-2-0-easy-fast-efficient-access-to-the-steem-blockchain","http://steemconnect.com/revoke/@busy.app"],"app":"steemit/0.1","format":"markdown"} |
created | 2018-02-05 11:31:45 |
last_update | 2018-02-05 11:31:45 |
depth | 0 |
children | 14 |
last_payout | 2018-02-12 11:31:45 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 21.860 HBD |
curator_payout_value | 7.269 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 3,300 |
author_reputation | 5,061,271,852,330 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 0 |
post_id | 35,123,632 |
net_rshares | 4,212,518,839,863 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
fabien | 0 | 1,337,188,294,968 | 100% | ||
cryptohazard | 0 | 8,208,036,720 | 100% | ||
busy.pay | 0 | 2,047,699,458,629 | 10% | ||
hellosteem | 0 | 1,100,779,581 | 100% | ||
alphacore | 0 | 556,798,773 | 1.2% | ||
gaman | 0 | 739,264,337,057 | 100% | ||
technerd888 | 0 | 77,282,091,729 | 100% | ||
ghostiee | 0 | 0 | 100% | ||
sattpaing | 0 | 644,526,692 | 100% | ||
pozmu | 0 | 0 | 100% | ||
fuzzyj | 0 | 0 | 100% | ||
practicalthought | 0 | 574,515,714 | 100% | ||
whtchpl | 0 | 0 | 100% | ||
wadew186 | 0 | 0 | 100% | ||
scienceblocks | 0 | 0 | 100% | ||
lnib | 0 | 0 | 100% | ||
cryptosproket | 0 | 0 | 100% |
Deffinitely We can trust on it.I agreed with you...
author | cryptostyle |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180205t154711963z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-02-05 15:47:18 |
last_update | 2018-02-05 15:47:18 |
depth | 1 |
children | 1 |
last_payout | 2018-02-12 15:47:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 51 |
author_reputation | 740,830,204,600 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 35,175,020 |
net_rshares | 0 |
Great to hear your affirmation. Cheers! :)
author | technerd888 |
---|---|
permlink | re-cryptostyle-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180206t133724466z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-02-06 13:37:27 |
last_update | 2018-02-06 13:37:27 |
depth | 2 |
children | 0 |
last_payout | 2018-02-13 13:37:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 42 |
author_reputation | 5,061,271,852,330 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 35,407,321 |
net_rshares | 0 |
i cant login into steemconnect, is the password the same as my master key then? im a little confused and its really aggravating me
author | dickcastle |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190217t024956430z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2019-02-17 02:49:57 |
last_update | 2019-02-17 02:49:57 |
depth | 1 |
children | 0 |
last_payout | 2019-02-24 02:49:57 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 131 |
author_reputation | 807,410,408 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 79,981,965 |
net_rshares | 0 |
Thanks for this post, really helpful :)
author | fuzzyj |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190118t073534000z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2019-01-18 07:35:39 |
last_update | 2019-01-18 07:35:39 |
depth | 1 |
children | 0 |
last_payout | 2019-01-25 07:35:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 39 |
author_reputation | 430,509,323 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 78,541,357 |
net_rshares | 0 |
Getting an error when I try to log in. Says not enough mana?
author | monker |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190421t075623538z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2019-04-21 07:56:24 |
last_update | 2019-04-21 07:56:24 |
depth | 1 |
children | 0 |
last_payout | 2019-04-28 07:56:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 61 |
author_reputation | 543,763,209,086 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 83,487,620 |
net_rshares | 0 |
But what, if http://steemconnect.com is ever hacked and manipulated to fish the Master passwords in this process ??
author | overunitydotcom |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180329t184050508z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"links":["http://steemconnect.com"],"app":"steemit/0.1"} |
created | 2018-03-29 18:40:51 |
last_update | 2018-03-29 18:40:51 |
depth | 1 |
children | 5 |
last_payout | 2018-04-05 18:40:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.031 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 115 |
author_reputation | 306,060,043,399 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 47,325,158 |
net_rshares | 10,836,080,013 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
overunitydotcom | 0 | 10,836,080,013 | 100% |
Hi @overunitydotcom, I'm not an expert in security. But I think getting hacked is certainly within the realm of possibility. There are some things we can do to reduce this possibility. First, make sure the steemconnect must be accessed via a secure HTTPS connection, so you'll need to make sure you see this on your browser: <center></center> Second, always use the Posting Key if all you're gonna be doing are upvoting, posting and commenting. If you do need to transfer Steem or SBD, or grant an app access to your account, use the Active Key. In short, never ever use your Owner Key -- reserve the owner key only for changing passwords. Third, if you have any SBD or Steem in your wallet, move them to Savings or Power Up to Steem Power. These should minimize your risk exposure. Hope this helps.
author | technerd888 |
---|---|
permlink | re-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180330t105119676z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"community":"busy","app":"busy/2.4.0"} |
created | 2018-03-30 10:51:30 |
last_update | 2018-03-30 10:51:30 |
depth | 2 |
children | 4 |
last_payout | 2018-04-06 10:51:30 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.106 HBD |
curator_payout_value | 0.034 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 931 |
author_reputation | 5,061,271,852,330 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 47,434,420 |
net_rshares | 46,864,915,570 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
technerd888 | 0 | 46,864,915,570 | 20% | ||
overunitydotcom | 0 | 0 | 100% | ||
remotehorst23 | 0 | 0 | 100% |
Hmm, but steeemconnect wants to have your master key, not just your posting key... So who is running Steemconnect.com ? They don´t even have an impressum ( about us) on their website... Why should I trust them with my master keys ???
author | overunitydotcom |
---|---|
permlink | re-technerd888-re-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180420t180656226z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-04-20 18:07:00 |
last_update | 2018-04-20 18:07:21 |
depth | 3 |
children | 2 |
last_payout | 2018-04-27 18:07:00 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.104 HBD |
curator_payout_value | 0.003 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 234 |
author_reputation | 306,060,043,399 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 51,168,768 |
net_rshares | 19,239,679,267 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
technerd888 | 0 | 9,267,443,984 | 3% | ||
overunitydotcom | 0 | 9,972,235,283 | 100% |
Where is then my Masterkey stored ? On the Steemconnect.com database or where ? Who can access it ?
author | overunitydotcom |
---|---|
permlink | re-technerd888-re-overunitydotcom-re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180420t180849208z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-04-20 18:08:51 |
last_update | 2018-04-20 18:08:51 |
depth | 3 |
children | 0 |
last_payout | 2018-04-27 18:08:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.087 HBD |
curator_payout_value | 0.003 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 99 |
author_reputation | 306,060,043,399 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 51,169,050 |
net_rshares | 15,933,743,548 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
technerd888 | 0 | 6,178,295,989 | 2% | ||
overunitydotcom | 0 | 9,755,447,559 | 100% | ||
pozmu | 0 | 0 | 100% | ||
steemsociety | 0 | 0 | 0% |
Informative post and comments, but I think it's generally a mess. Steemit should have this feature built-in, we shouldn't have to use 3rd party website. > They don't store the keys that you enter in steemconnect. Ok, that's interesting, so where is it stored? In a cookie? I hope it's at least properly encrypted... **Edit:** Maybe I was too harsh calling it a mess, we have to remember it's all build on top of blockchain.
author | pozmu |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180808t163555861z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-08-08 16:35:51 |
last_update | 2018-08-08 17:04:54 |
depth | 1 |
children | 0 |
last_payout | 2018-08-15 16:35:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 427 |
author_reputation | 1,193,834,520 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 67,545,053 |
net_rshares | 0 |
I’ve been using Steemconnect on Musing and dLike... however today upon trying to login, it doesn’t offer the option to click my usual account, but it starting from scratch asking for my username and key - which has never happened since I first input it months ago... Wondering if this is anything to be concerned about, if there has been an app-wise reset, this is normal, etc... you happen to know what's up?
author | rok-sivante |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20190130t234141699z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2019-01-30 23:41:42 |
last_update | 2019-01-30 23:41:42 |
depth | 1 |
children | 0 |
last_payout | 2019-02-06 23:41:42 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 411 |
author_reputation | 664,589,362,019,250 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 79,186,019 |
net_rshares | 2,679,179,875 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
elviento | 0 | 2,679,179,875 | 3% |
thanks, i have had the same concerns, but now I am going to use steemconnect
author | yardne |
---|---|
permlink | re-technerd888-on-sharing-keys-and-passwords-with-steemconnect-how-safe-is-it-20180605t203346748z |
category | steemconnect |
json_metadata | {"tags":["steemconnect"],"app":"steemit/0.1"} |
created | 2018-06-05 20:33:48 |
last_update | 2018-06-05 20:33:48 |
depth | 1 |
children | 0 |
last_payout | 2018-06-12 20:33:48 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 76 |
author_reputation | 1,008,468,376,448 |
root_title | "On Sharing Keys and Passwords with SteemConnect: How Safe Is It?" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 59,426,322 |
net_rshares | 0 |