RE: Offline Attack on Steem User Credentials by robinhood
Viewing a response to: @robinhood/offline-attack-on-steem-user-credentials
steem·@arhag·
0.000 HBDYup, this is exactly what I have been shouting about for weeks now and expected would eventually happen. I am happy that you are a white hat and didn't take control of the accounts for yourself to profit from. I believe it is better to push away new users with less user friendly registration (that forces them to use a randomly generated key that they must store securely and use password managers to manage) than to bring them aboard easily only to completely piss them off when their account or funds are stolen [1]. It is our job to make it as user-friendly as possible and to provide great resources educating users how to generate and manage random high-entropy passwords. But I don't agree with compromising their security because it is "too hard" and we don't want to lose them as new users. [1] Although the new recovery feature allows them to get their account back. Most funds are usually locked in the time-locked Steem Power, so hopefully not too much financial damage would be done by the time they recover their account. And there are plans for a user opt-in and configurable time-locked savings account to even protect their more liquid STEEM and Steem Dollar funds from being stolen by hackers assuming they recover their account in a few days.
👍 jason, artific, robinhood, nikolai, cass, emule, ma3, tinfoilfedora, pharesim, oneyesoneno, pheonike, calamus056, pastemaster, zozian, satch, papa-smurf, karnal, wackou, alphabeta, mikeinfla, judyhopps, illuminatidude, masterinvestor, coininstant, summon, artificial, funcal, eric-boucher, proctologic, ajvest, alecsinspace, steempty, brennanhm, mranderson, radioogaga, cathou009, java1959, cannav, robrigo, mianeri, mazainderan, dtsddace, lovejoy, cybercodetwins, toddl984,