RE: IMPORTANT !!! Vulnerability in password protection for accounts

You are viewing a single comment's thread from:

IMPORTANT !!! Vulnerability in password protection for accounts

in vulnerability •  8 years ago  (edited)

afaik, there is an email notification service in development that will address this and other cases.

Thank you for bringing it up.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Hi. I am not sure how to tell if there is a problem. I went to "stolen account recovery". If all is well, what message will I see there?

Thank you

Your Recovery account - steem. All is well. https://steemd.com/@hanshotfirst

A message/alert on Steemit itself, in addition to an email, would be a good measure. I think a lot of people use application-specific email addresses to register on Steemit and probably don't check them often or at all.

Good point.

E-mail is an already archaic technology. What about people that used disposable e-mails? (It turns out that cryptoenthusiasts are also fanatics of never disclosing personal data to anyone).

Perhaps using a signed message from another key could be used (a configurable bitcoin wallet, perhaps?)

To change (whatever), please sign this message with (BTC address; that should also require a signed message to be changed):
"Change the data of my account: TIMESTAMP"