create account

RE: Let Zappl Clerify some things. FUD Correction by inertia

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @zappl/let-zappl-clerify-some-things-fud-correction

· @inertia ·
$72.20
Please clarify this then: https://github.com/Zappl/Zappl/issues/5
👍  , , , , , , , ,
properties (23)
authorinertia
permlinkre-zappl-let-zappl-clerify-some-things-fud-correction-20180212t091938864z
categoryzappl
json_metadata{"tags":["zappl"],"links":["https://github.com/Zappl/Zappl/issues/5"],"app":"steemit/0.1"}
created2018-02-12 09:19:39
last_update2018-02-12 09:19:39
depth1
children35
last_payout2018-02-19 09:19:39
cashout_time1969-12-31 23:59:59
total_payout_value60.838 HBD
curator_payout_value11.358 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length65
author_reputation346,568,901,399,561
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id36,887,133
net_rshares9,776,837,362,035
author_curate_reward""
vote details (9)
@reggaemuffin · (edited)
$23.88
If they say they don't save the keys, the should not save the keys. Looks like security not being taken seriously there. No fud, just open source reviews...


https://user-images.githubusercontent.com/494368/36068954-8efdd9ac-0e95-11e8-82c9-559b76ebc369.png
👍  , , , , , , , , , , ,
properties (23)
authorreggaemuffin
permlinkre-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180212t170047958z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1","image":["https://user-images.githubusercontent.com/494368/36068954-8efdd9ac-0e95-11e8-82c9-559b76ebc369.png"]}
created2018-02-12 17:00:48
last_update2018-02-12 17:14:06
depth2
children34
last_payout2018-02-19 17:00:48
cashout_time1969-12-31 23:59:59
total_payout_value18.378 HBD
curator_payout_value5.499 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length257
author_reputation37,964,839,695,531
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id36,981,951
net_rshares3,282,218,936,955
author_curate_reward""
vote details (12)
@inertia ·
$0.03
Yup, there's no need for FUD.  I just look at network activity.

> Zappl is open source you can contribute to the Github or leave bug reports on utopian.

That's highly debatable when there have been only small commits since November, 2017.  My bug report was created by utopian, twice for some reason, then closed with no explanation and no related commits.

To me, it seems like the Zappl front-end was put on GitHub so it would qualify for utopian's rules.  But it hasn't been maintained.

> No Zappl don't save keys, your keys are saved in your browser or mobile device not on our servers.

Maybe this is true, but it's beside the point.  It's possible that Zappl signs in-browser, but it also sends the keys to the server.  Since the keys *are* sent to the server, it's entirely possible that they're logging keys without knowing it.

> Even if Zappl was capturing keys for the public key (Which were not because they're saved in your browser)were only limited to those uses above.

This is where we get into a real problem.  Certain parts of Zappl does ask for the active key and does send the active key to the server.  My GitHub Issue shows this.
👍  ,
properties (23)
authorinertia
permlinkre-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180212t172624074z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-12 17:26:24
last_update2018-02-12 17:26:24
depth3
children20
last_payout2018-02-19 17:26:24
cashout_time1969-12-31 23:59:59
total_payout_value0.032 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,154
author_reputation346,568,901,399,561
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id36,987,146
net_rshares5,212,256,104
author_curate_reward""
vote details (2)
@reggaemuffin ·
$0.10
Exactly. Them trying to cover it just makes it worse...
👍  , , ,
properties (23)
authorreggaemuffin
permlinkre-inertia-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180212t173509662z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-12 17:35:12
last_update2018-02-12 17:35:12
depth4
children4
last_payout2018-02-19 17:35:12
cashout_time1969-12-31 23:59:59
total_payout_value0.096 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length55
author_reputation37,964,839,695,531
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id36,988,740
net_rshares13,722,422,052
author_curate_reward""
vote details (4)
@zappl · (edited)
Yup, there's no need for FUD. I just look at network activity.

    Zappl is open source you can contribute to the Github or leave bug reports on utopian.

That's highly debatable when there have been only small commits since November, 2017. My bug report was created by utopian, twice for some reason, then closed with no explanation and no related commits.

#### Reply:
There was significant updates to the project just 18 days ago. So its pretty open source. All one needs to do is just download the source and they can run it in dev mode and set up some pm2 starts for mongod and index.js but npm start dev would be easier to do.

The website will work the same way it does on the web, The only difference is they won't be able to upload videos and images, they will need to add those keys for them self.

https://github.com/Zappl/Zappl/commit/f83e3130b005008317e73748da82b08fb01c0204

<hr>

To me, it seems like the Zappl front-end was put on GitHub so it would qualify for utopian's rules. But it hasn't been maintained.

    No Zappl don't save keys, your keys are saved in your browser or mobile device not on our servers.

Maybe this is true, but it's beside the point. It's possible that Zappl signs in-browser, but it also sends the keys to the server. Since the keys are sent to the server, it's entirely possible that they're logging keys without knowing it.

    Even if Zappl was capturing keys for the public key (Which were not because they're saved in your browser)were only limited to those uses above.

This is where we get into a real problem. Certain parts of Zappl does ask for the active key and does send the active key to the server. My GitHub Issue shows this.

#### Reply:
Yes were aware active keys transactions, we have had several talks about this on discord before. The review was closed because its in an up and coming update. We tend to do bulk updates with our code.  As one can see from our latest updates from January 

We first update in a private rep then those updates are moved over to the main open rep. As a company we have plugins for our code thats are trade secret plugins. 

For some things zappl wants a competitive edge, but we still leave the code that connects these features open to the public. So if they would want to make plugins with these features they can do so their self and see how this is interacting with the code.


Were not trying to hide anything just sometimes we happen to close things with out commenting on them. Which honestly we probably shouldn't have been doing. If you look at the tickets we have closed tickets with out commenting, but the fix had still been put in.

So we will try to update users of fixes before we close tickets now.
👍  
properties (23)
authorzappl
permlinkre-inertia-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180212t234258812z
categoryzappl
json_metadata{"tags":["zappl"],"links":["https://github.com/Zappl/Zappl/commit/f83e3130b005008317e73748da82b08fb01c0204"],"app":"steemit/0.1"}
created2018-02-12 23:43:00
last_update2018-02-12 23:57:51
depth4
children14
last_payout2018-02-19 23:43:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length2,712
author_reputation41,244,449,218,741
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,055,145
net_rshares0
author_curate_reward""
vote details (1)
@jimshorts ·
Can you help me figure out how much zappl is taking from people's posts? I never read anywhere they would take a cut of my post's profits but it appears they took 3%.
properties (22)
authorjimshorts
permlinkre-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180215t055709250z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-15 05:57:09
last_update2018-02-15 05:57:09
depth3
children2
last_payout2018-02-22 05:57:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length166
author_reputation4,773,873,072,954
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,661,179
net_rshares0
@fraenk ·
they take 15% of rewards (compared to dtube/dsound/dmania's 25% that's low I guess)

![](https://steemitimages.com/DQmTFBCxdovvpLPpWCujEYnNqnq7gizvEi5v5cfhWQ2okeQ/image.png)
properties (22)
authorfraenk
permlinkre-jimshorts-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180215t114634340z
categoryzappl
json_metadata{"tags":["zappl"],"image":["https://steemitimages.com/DQmTFBCxdovvpLPpWCujEYnNqnq7gizvEi5v5cfhWQ2okeQ/image.png"],"app":"steemit/0.1"}
created2018-02-15 11:46:33
last_update2018-02-15 11:46:33
depth4
children0
last_payout2018-02-22 11:46:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length173
author_reputation17,144,676,870,084
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,726,354
net_rshares0
@reggaemuffin ·
$0.10
They probably take a beneficiary like many other platforms, not sure how much
👍  , , ,
properties (23)
authorreggaemuffin
permlinkre-jimshorts-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180215t062556456z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-15 06:25:54
last_update2018-02-15 06:25:54
depth4
children0
last_payout2018-02-22 06:25:54
cashout_time1969-12-31 23:59:59
total_payout_value0.104 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length77
author_reputation37,964,839,695,531
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,666,773
net_rshares15,687,500,488
author_curate_reward""
vote details (4)
@zappl · (edited)
$1.49
Please read to the bottom of me and inertia conversation. We don't save keys.
👍  ,
properties (23)
authorzappl
permlinkre-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180213t020456698z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-13 02:04:57
last_update2018-02-13 02:05:18
depth3
children9
last_payout2018-02-20 02:04:57
cashout_time1969-12-31 23:59:59
total_payout_value1.487 HBD
curator_payout_value0.004 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length77
author_reputation41,244,449,218,741
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,081,279
net_rshares205,693,999,256
author_curate_reward""
vote details (2)
@elmubareki ·
$0.02
They do not believe it yet. And With time, they will believe.

## Zappl just has to keep giving trust to users, that's all. And Never make mistakes.
👍  
properties (23)
authorelmubareki
permlinkre-zappl-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180213t021239158z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-13 02:13:15
last_update2018-02-13 02:13:15
depth4
children4
last_payout2018-02-20 02:13:15
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length148
author_reputation22,740,889,959,243
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,082,892
net_rshares3,012,644,096
author_curate_reward""
vote details (1)
@reggaemuffin ·
Seems you don't save keys, but if they so happen to be leaked in logs, the fix for that will take weeks?

I am not impressed by how you handled this and will advise everyone to change their keys if they used zappl. 

Should you have the fix live at some point, please comment on the github issue.
👍  
properties (23)
authorreggaemuffin
permlinkre-zappl-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180213t061003059z
categoryzappl
json_metadata{"tags":["zappl"],"app":"steemit/0.1"}
created2018-02-13 06:10:03
last_update2018-02-13 06:10:03
depth4
children2
last_payout2018-02-20 06:10:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length296
author_reputation37,964,839,695,531
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,131,174
net_rshares2,783,737,854
author_curate_reward""
vote details (1)
@richalyandesty ·
Oke sir zappl thank you
properties (22)
authorrichalyandesty
permlinkre-zappl-re-reggaemuffin-re-inertia-re-zappl-let-zappl-clerify-some-things-fud-correction-20180213t033903577z
categoryzappl
json_metadata{"tags":["zappl"],"community":"busy","app":"busy/2.3.0"}
created2018-02-13 03:39:09
last_update2018-02-13 03:39:09
depth4
children0
last_payout2018-02-20 03:39:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length23
author_reputation772,042,122,996
root_title"Let Zappl Clerify some things. FUD Correction"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id37,100,224
net_rshares0