create account

RE: A new approach to Content Reward Allocation by censor-this

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @smooth/re-dantheman-a-new-approach-to-content-reward-allocation-20160603t013625900z

· @censor-this ·
>Huh? I thought the private keys are client-side.


I don't think so in this case. Augur has client side keys but that means I have to export my account and upload it to another computer if I want to use it there. I can log into this account from any computer I've tried. Maybe I'm wrong and they've worked some magic. If so, I hope they share it with the Augur guys.
properties (22)
authorcensor-this
permlinkre-smooth-re-dantheman-a-new-approach-to-content-reward-allocation-20160603t014923278z
categorysteem
json_metadata{"tags":["steem"]}
created2016-06-03 01:49:27
last_update2016-06-03 01:49:27
depth2
children2
last_payout2016-08-18 12:55:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length367
author_reputation1,720,978,822,824
root_title"A new approach to Content Reward Allocation"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id22,150
net_rshares0
@abit ·
The private key IS client-side, but in this system it's derived from a combination of your password (only you know) and some other info (known by the service), aka a "brain key". You can also export the WIF to other computer, and use it directly (forget the password).
properties (22)
authorabit
permlinkre-censor-this-re-smooth-re-dantheman-a-new-approach-to-content-reward-allocation-20160603t121755052z
categorysteem
json_metadata{"tags":["steem"]}
created2016-06-03 12:17:54
last_update2016-06-03 12:17:54
depth3
children1
last_payout2016-08-18 12:55:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length268
author_reputation141,171,499,037,785
root_title"A new approach to Content Reward Allocation"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id22,515
net_rshares0
@arhag ·
That makes it sound like the other info is only known by the service and the user the service shares it with, which isn't true. The other info is public knowledge. Which means someone who has (or guesses) your password can derive all your private keys (unless you changed them from their default after registering with Facebook or Reddit).

So to everyone reading this: you better be using a **strong**[1] and **unique**[2] password. The best approach is to use a password manager and have the password manager generate the password with 256-bits of entropy for you. Also, it is better to have a separate password for your owner key that you normally keep securely stored offline (with some redundancy is a good idea too).

[1] By strong, I don't only mean long. Steemit requires that you use at least 16 characters. But if your password is, for example, just some combination of your full name plus birth date, then it isn't strong because it can easily be brute forced by a hacker targeting you specifically who knows your identity (by following the linked Facebook account perhaps).

[2] Unique is important because if you reuse the same password you use on some other service, and that service gets hacked (and they had bad security practices so that they were holding your plain-text password in their database), then a hacker who gets that hacked information from the black market can try those passwords out on your account.
properties (22)
authorarhag
permlinkre-abit-re-censor-this-re-smooth-re-dantheman-a-new-approach-to-content-reward-allocation-20160603t182231607z
categorysteem
json_metadata{"tags":["steem"]}
created2016-06-03 18:22:30
last_update2016-06-03 18:22:30
depth4
children0
last_payout2016-08-18 12:55:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,431
author_reputation52,490,827,205,383
root_title"A new approach to Content Reward Allocation"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id22,824
net_rshares0