RE: SteemConnect V3 Beginner's Guide

You are viewing a single comment's thread from:

SteemConnect V3 Beginner's Guide

in hive-111390 •  5 years ago 

Thanks for the effort, @gadrian, but I did not ask how the apps are working. My question was: “why Busy.org and Steempeak.com do not have one simple option of login with a posting password?” You know, just for posting and voting, like you can do it at the official Steemit.com page.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

You mean without SteemConnect, to enter the private key directly?

Yes.

Because that's not safe/recommended.

I would understand if you said “more convenient”, @gadrian, but… Why it would one password on SteemConnect be more secure than four different level passwords at Steemit security management? What if user exposes this one password to the smartphone data thieves?

Why not leave the option just for posting password for those who want to live dangerously? Like we did do it on Steemit.com? Why not let people decide on their own what is more secure for them?

Why it would one password on SteemConnect be more secure than four different level passwords at Steemit security management?

The private keys are encrypted on your own device. Someone needs access to your device, and nobody is crazy enough to even bother trying to break the encryption. That's why the most common attack vector is phishing or hunting user errors.

Plus, if you would have read my guide you would know on SteemConnect only private posting key are stored, not any of the others.

Why not let people decide on their own what is more secure for them?

Most people don't give importance to security until they lose their accounts and it may be too late for them.

The most dangerous thing to a user's account is the user himself.

If you want to live dangerously, be my guest, but overall an application has to take a responsible approach.

The private keys are encrypted on your own device. Someone needs access to your device, and nobody is crazy enough to even bother trying to break the encryption.

He doesn’t need to bother with encryption if he gets the SteemConnect password. Are we talking about the same things?

Yes we are talking about the same things.

The SteemConnect password is a way to unlock access to verify the private key that is stored. But the private key is stored encrypted.

OK, just one more step: When someone gets your SteemConnect password, he has a full access to your account, right?