create account

RE: Denial of Service Vulnerability Fix by andrarchy

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @glenalbrethsen/re-steemitblog-denial-of-service-vulnerability-fix-20190417t025941756z

· @andrarchy ·
$0.03
I believe this will be fixed, but it is much easier to discuss and address UX issues like this if a PR is submitted and shared. Then I can say whether the PR will be approved or not. Also it may well be the case that a PR has already been submitted, in which case we can skip the discussion and move straight to the meat, "Will this get merged." The goal is to fix all UX issues so that it is a seamless experience, so any poor UX should be resolved.
👍  
properties (23)
authorandrarchy
permlinkre-glenalbrethsen-re-steemitblog-denial-of-service-vulnerability-fix-20190417t175626951z
categorysteem
json_metadata{"tags":["steem"],"app":"steemit/0.1"}
created2019-04-17 17:56:27
last_update2019-04-17 17:56:27
depth2
children3
last_payout2019-04-24 17:56:27
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.006 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length450
author_reputation230,168,201,522,782
root_title"Denial of Service Vulnerability Fix"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id83,272,522
net_rshares45,580,768,460
author_curate_reward""
vote details (1)
@glenalbrethsen ·
Hey, @andrarchy

I think I'm looking at the PR list on steemit/steem's github now. I don't see anything. The most recent thing has to do with the Steem Proposal System (worker proposals via blocktrades), and some median feed update from 29 days ago.

Can anyone submit a pull request? I wouldn't know where to begin. I'm sure there's more technical terms for "stay logged in check box when checked doesn't stay logged in." :) I'm willing to learn, though, I'd just need to be pointed in the direction of some tutorials or something.
properties (22)
authorglenalbrethsen
permlinkre-andrarchy-re-glenalbrethsen-re-steemitblog-denial-of-service-vulnerability-fix-20190417t203642373z
categorysteem
json_metadata{"tags":["steem"],"users":["andrarchy"],"app":"steemit/0.1"}
created2019-04-17 20:36:42
last_update2019-04-17 20:36:42
depth3
children2
last_payout2019-04-24 20:36:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length532
author_reputation123,853,032,378,097
root_title"Denial of Service Vulnerability Fix"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id83,279,090
net_rshares0
@andrarchy ·
$0.02
Are you using your active key to sign in to steemitwallet.com? The active key is not cached because that would put them at risk re: hacking. If you are using your posting key to sign into steemitwallet, this should not be happening. Also if you sign in with your master password this should not be happening because that is used to derive your posting key which would then be cached.

So if you're using your active key then this is the desired behavior, but if not, let me know as that would be a bug.
👍  
properties (23)
authorandrarchy
permlinkre-glenalbrethsen-re-andrarchy-re-glenalbrethsen-re-steemitblog-denial-of-service-vulnerability-fix-20190417t213725709z
categorysteem
json_metadata{"tags":["steem"],"app":"steemit/0.1"}
created2019-04-17 21:37:24
last_update2019-04-17 21:37:24
depth4
children1
last_payout2019-04-24 21:37:24
cashout_time1969-12-31 23:59:59
total_payout_value0.018 HBD
curator_payout_value0.005 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length502
author_reputation230,168,201,522,782
root_title"Denial of Service Vulnerability Fix"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id83,281,442
net_rshares43,957,178,447
author_curate_reward""
vote details (1)
@glenalbrethsen ·
hey, @andrarchy.

I guess I was using the Active key, which is odd, since I thought I'd changed it to the posting key. However, I just did make the change, and it seems to be doing what I would like it to do, so thanks for the IT help. :)
properties (22)
authorglenalbrethsen
permlinkre-andrarchy-re-glenalbrethsen-re-andrarchy-re-glenalbrethsen-re-steemitblog-denial-of-service-vulnerability-fix-20190427t001007373z
categorysteem
json_metadata{"tags":["steem"],"users":["andrarchy"],"app":"steemit/0.1"}
created2019-04-27 00:10:06
last_update2019-04-27 00:10:06
depth5
children0
last_payout2019-05-04 00:10:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length238
author_reputation123,853,032,378,097
root_title"Denial of Service Vulnerability Fix"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id83,816,771
net_rshares0