From my understanding the hack was initiated through some kind of XSS attack, which is a browser based hidden code that enabled the hacker to swipe the keys being used
We could go into detail about the technicalities of what that means but in a more general sense it was a basically a hacker STD. Yep a sexually transmitted hacker disease!
When you interacted with a hacked users post, by up/down voting or commenting you would give away the keys to your account.
They would then empty your account and post under your name, hiding the secret hacker STD code and infect other users.
This could have gotten way out of control. But the developers shut it down before some serious damage could be done.
How did I figure it out before I could be drained?.... I was incredibly lucky.
Someone mentioned that there was a hack going on in the slack, referencing a @dantheman post. So I was already on guard and looking for things that seemed out of place.
I viewed this post by @dantheman.
It's been edited now, but it was very out of character, I downvoted it because it looked like someone else was using his account.
I then went to look at Bittrex to see what was going on and I realized that the hack could have potentially been site wide.
I noticed that the memos (the text in red) were the same for several accounts. I also knew from reading @complexring and @samupaha s posts and interacting on Slack that they were not the same person.
Going back to the @dantheman post I noticed that some of those names had interacted with the post and some of the downvotes had been removed. So I removed mine - I think I was already hacked at this point.
I then initiated the transfer out with minutes to spare...
I was probably one of the last accounts to be hacked before the site shut down to contain it, I was lucky to have access to more information than most of the other accounts.
I was just using my master password for everything, it was 30 characters long and completely random. It wasn't enough safety.
Now, with the help of a few articles….
Can you remember your Steemit password? If so, you are in danger.
by @arhag
Steemit - Security - Exchanges & Why - By a guy that has been in Crypto since 2009 - [NEW PEOPLE - READ THIS NOW]
by @fyrstikken
…I'm signed into my account with my posting key
My master password is now 100+ characters long of completely random characters and symbols. I use a password manager.
When I want to initiate a transfer of Steem or Steem Dollars I'll use my active key to do so and then quickly log in again with my posting key. I will NOT interact with any posts in this time.
The particular hack that came about, I believe has been patched.
...Will there be more holes in the future?...
...most likely, but if I use a posting key for posts and votes and then using my active key solely for transferring I will likely be much better protected from any similar hacks in the future.
I was lucky. Really lucky.
If you've been procrastinating setting up your security then get on it now! The posts above will help you figure it out.
If thats not enough... read this recent post from @cass
Compromised account @katecloud
and this whitehat (friendly hacker) hack from @robinhood - who managed to break the passwords of around 500 accounts
Offline Attack on Steem User Credentials
Wake the fuck up and get it sorted!
The guides above will help you sort it out. It basically comes down to picking a ridiculously long master password, taking note of your private keys in the permissions section and then just using your private posting key for day to day use.
I'm probably being dense - but could Steemit prevent future hacks by preventing people putting XSS (whatever that is) on their posts?
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Not sure of the technicalities, but it seems like these sort of attacks are always a vulnerability. Especially with such an obvious target on Steemits back. I think the developers will sort something out in the future, over time.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
No, it's a trojan script in the HTML web pages you load on Steemit. Dan had a post where he said you cannot stop it, one can only minimize it. The whales are safe because they use the CLI steemd to do money transfers, not the web site. I won't feel safe until I'm using CLI steemd for everything.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
An STHD haha. Thanks for the tips! And in the long run hopefully the response to this attack will make future attacks less likely.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Haha, I hope so too.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I joined up right after the hack. Glad I wasn't here for that, but I have to say - good eye. This is the kind of information that's handy for us all in the future should something similar happen again.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Hopefully the steps taken will sort it all out. The recovery option and having another user or third party available to confirm your identity should help. You should however make sure to use your posting key so your account can be recovered before any liquid funds are transferred.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Damn worried about hackers on here lol, good on you for looking out for this stuff. any chance you know how to put separate password for owner, can't seem to change anything in preferences.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Click your photo in the top right, go to permissions. Then click 'change password'.
After that create a huge random password and store it in a password manager.
Take note of your private keys by making them visible.
Login with your name/posting and then the private posting key as your password. Only use your posting key in day to day use then use your owner account when you want to make transfers.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Security must be a key element at steemit if we want it to success, thank you very much for share this really usefull info
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Excellent info and links and definitely a wake up call. I thought my password was quite good - maybe for everyday usage but certainly not for this site. There is no way I would have spotted everything you did so I'll be following the tips and sorting out my security.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I was just lucky, I had access to more info than the accounts that were hacked before me. I was hoping to get this kind of response, so thanks for commenting!
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Thanks for this. All users here must understand that you must be careful about the posts you interact with and you must be smart about passwords. I continue to think privacy on Steemit is a big problem, but its encouraging to know the dev team is working on it https://steemit.com/steemit/@ntomaino/does-the-steem-community-care-about-privacy
But
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Yep, good to see @dan responded. I was thinking almost a separate account would have to be made to hide any liquid funds, however his option seems like a good one.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
That's some freaky stuff man! Do you have password managers that you'd recommend for new Steemians?
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
strongly recommend 1password
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I use SafeinCloud, it's a one time low payment to get full access and it syncs with my phone with a fingerprint password. Some of the other managers ask for like $30 a year. I also use Roboform on my desktop, I'd recommend both.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I buy Ethereum and hackers attack the DAO. I buy steem and hackers attack Steemit. I am a Jinx
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Haha, it's always going to happen. Sometimes you have to get slapped down to really take a good look at security. In the case of the DAO and the Steemit hack... security didn't do much they still got hacked. I'll be keeping a much more vigilant eye on how to be secure in the future. You'd think after losing money with MtGox and Cryptsy I'd have sorted it out by now... we always have something to learn.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
This is a very good summation. Thank you for this post. It does save a lot of trying to wade through the influx of posts.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Thanks. I think the main point of me posting was to rally up some people to take action. Even though I was quick enough to react, even though I had a secure password... I was still hacked. It doesn't take much time, get your security sorted.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I was lucky enough to have survived. But I didn't have anything to lose as well as I literally joined the day before!! Anyways the Steemit team did a really nice job of containing it.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Yep. Get onto securing your account now. It's a few minutes of your time and you'll feel much better once you've done it.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
yeah did that as well! I have GOT to stop procrastinating on things!! LOL
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
haha! Good stuff!
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
I finally stumbled on real, complete and interesting article! Good job!That's what I personaly would like to read
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit
Great to warn everyone out there! Thanks a lot for this :)
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit