Steemauto stores your passwords in raw format! by emrebeyler

View this thread on steempeak.com
· @emrebeyler · (edited)
$60.46
Steemauto stores your passwords in raw format!
When you click *"lost password"* at [Steemauto](https://steemauto.com), It will send your password directly to your email. That means, passwords are stored raw in their database.

<center>![Screen Shot 2018-03-12 at 13.52.54.png](https://res.cloudinary.com/hpiynhbhq/image/upload/v1520852771/ctjl1thh4bvn85wejyhw.png)</center>

This is one of the sins of web application development practices. If the system can send you back your password, that means the application **stores your pasword as plain text.**.  

That's extremely dangerous.  If a thief or attacker get the database somehow, they would have every users credentials as well. 

#### Best practice
***

- Salt and hash each password
- Use good hashing functions like Bcrypt instead of md5 or sha1
- Store SALT + HASH in the database instead of raw password

That way you can't send the password back to users but  you may create unique tokens for password regeneration and deal with the recovery as an application developer.

#### What to do as a user?
***

**Use a throw-away and unique password at Steemauto.**

That's the general rule but I am pretty sure %90 of the users, using a generic password that they use on their daily life. If  Steemauto database leaks to some bad-minded parties, your accounts will be in great danger.

#### *Edit: @mahdiyari addressed the issue*
***

*He removed the username-password authentication and started using SteemConnect for it. Thanks for the fast response!*
๐Ÿ‘  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 114 others
properties (23)
post_id38,135,086
authoremrebeyler
permlinksteemauto-store-your-passwords-in-raw-format
categorysteemauto
json_metadata"{"format": "markdown", "image": ["https://res.cloudinary.com/hpiynhbhq/image/upload/v1520852771/ctjl1thh4bvn85wejyhw.png"], "links": ["https://steemauto.com"], "tags": ["steemauto", "steem", "security", "sndbox", "busy"], "app": "steemit/0.1", "users": ["mahdiyari"], "community": "busy"}"
created2018-03-12 11:08:51
last_update2018-03-12 22:37:42
depth0
children38
net_rshares19,448,740,407,706
last_payout2018-03-19 11:08:51
cashout_time1969-12-31 23:59:59
total_payout_value49.021 SBD
curator_payout_value11.438 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length1,462
author_reputation319,480,565,467,431
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (178)
@muratti ·
Bilgi iรงin รงok teลŸekkรผrler รผstad.
properties (22)
post_id38,135,387
authormuratti
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t111317256z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 11:11:24
last_update2018-03-12 11:11:24
depth1
children0
net_rshares0
last_payout2018-03-19 11:11:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length33
author_reputation67,091,370,995
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@tts ·
To listen to the audio version of this article click on the play image.
[![](https://s18.postimg.org/51o0kpijd/play200x46.png)](http://ec2-52-72-169-104.compute-1.amazonaws.com/emrebeyler__steemauto-store-your-passwords-in-raw-format.mp3)
Brought to you by [@tts](https://steemit.com/tts/@tts/introduction). If you find it useful please consider upvote this reply.
๐Ÿ‘  
properties (23)
post_id38,136,867
authortts
permlinkre-steemauto-store-your-passwords-in-raw-format-20180312t112308
categorysteemauto
json_metadata{}
created2018-03-12 11:23:09
last_update2018-03-12 11:23:09
depth1
children0
net_rshares576,358,415
last_payout2018-03-19 11:23:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length364
author_reputation-4,535,933,372,579
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@synergysteem ·
$0.03
Passwords and authentication are often not programmed well, good public service announcement.
๐Ÿ‘  ,
properties (23)
post_id38,137,638
authorsynergysteem
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t112836612z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 11:28:36
last_update2018-03-12 11:28:36
depth1
children0
net_rshares8,856,405,512
last_payout2018-03-19 11:28:36
cashout_time1969-12-31 23:59:59
total_payout_value0.025 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length93
author_reputation40,947,012,609
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@themarkymark ·
$0.09
I talked to him about a week ago why an email and password is needed.  SteemConnect w/ posting authority would be so much more secure and painless.
๐Ÿ‘  ,
properties (23)
post_id38,147,290
authorthemarkymark
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t123832376z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 12:38:39
last_update2018-03-12 12:38:39
depth1
children3
net_rshares30,814,511,851
last_payout2018-03-19 12:38:39
cashout_time1969-12-31 23:59:59
total_payout_value0.073 SBD
curator_payout_value0.020 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length147
author_reputation806,615,692,176,612
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@leprechaun ·
Too bad SC demands the active key.
properties (22)
post_id38,226,143
authorleprechaun
permlinkre-themarkymark-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t213441377z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 21:34:51
last_update2018-03-12 21:34:51
depth2
children2
net_rshares0
last_payout2018-03-19 21:34:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length34
author_reputation3,043,219,887,107
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@themarkymark ·
Yes, but it is fairly trusted and it is only used locally and not saved.
properties (22)
post_id38,226,330
authorthemarkymark
permlinkre-leprechaun-re-themarkymark-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t213613879z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 21:36:12
last_update2018-03-12 21:36:12
depth3
children1
net_rshares0
last_payout2018-03-19 21:36:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length72
author_reputation806,615,692,176,612
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@kilianparadise ·
Thank you for sharing this important information @emrebeyler.
Thumbs up!!!!
properties (22)
post_id38,148,082
authorkilianparadise
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t124303038z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "users": ["emrebeyler"], "tags": ["steemauto"]}"
created2018-03-12 12:43:15
last_update2018-03-12 12:43:15
depth1
children0
net_rshares0
last_payout2018-03-19 12:43:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length75
author_reputation5,843,414,133,735
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@yulem ·
$0.02
Other than selecting "Lost Password?" there doesn't appear to be any way to manage passwords. :-(
๐Ÿ‘  
properties (23)
post_id38,148,493
authoryulem
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t124544422z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 12:45:45
last_update2018-03-12 12:45:45
depth1
children2
net_rshares8,266,725,377
last_payout2018-03-19 12:45:45
cashout_time1969-12-31 23:59:59
total_payout_value0.018 SBD
curator_payout_value0.005 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length97
author_reputation376,318,488,374
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@emrebeyler ·
Yeah, seens like you cannot change it.
๐Ÿ‘  
properties (23)
post_id38,181,473
authoremrebeyler
permlinkre-yulem-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t161438911z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 16:14:39
last_update2018-03-12 16:14:39
depth2
children1
net_rshares2,836,069,968
last_payout2018-03-19 16:14:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length38
author_reputation319,480,565,467,431
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@fan1 ·
this is very important information, thank you
properties (22)
post_id38,185,892
authorfan1
permlinkre-emrebeyler-re-yulem-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t164331916z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 16:43:30
last_update2018-03-12 16:43:30
depth3
children0
net_rshares0
last_payout2018-03-19 16:43:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length45
author_reputation16,176,661,164
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@flugschwein ·
Wow, that's some ridiculous stuff imo. I thought literally no one stores passwords that way these days.
properties (22)
post_id38,149,415
authorflugschwein
permlinkre-emrebeyler-2018312t135120120z
categorysteemauto
json_metadata"{"app": "esteem/1.5.1", "format": "markdown+html", "community": "esteem", "tags": ["steemauto", "steem", "security", "sndbox", "busy"]}"
created2018-03-12 12:51:33
last_update2018-03-12 12:51:33
depth1
children0
net_rshares0
last_payout2018-03-19 12:51:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length103
author_reputation8,232,951,472,484
root_title"Steemauto stores your passwords in raw format!"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@mesutbahar ·
$0.02
Eline yรผreฤŸine saฤŸlฤฑk kardeลŸim iลŸllah daha รงok kazanฤฑrsฤฑn.
๐Ÿ‘  
properties (23)
post_id38,153,340
authormesutbahar
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t131614589z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 13:16:27
last_update2018-03-12 13:16:27
depth1
children0
net_rshares8,267,164,766
last_payout2018-03-19 13:16:27
cashout_time1969-12-31 23:59:59
total_payout_value0.018 SBD
curator_payout_value0.005 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length58
author_reputation-16,426,897,814
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@fr3eze ·
Good to know that, may be a 2FA implementation could solve that. But they should not store sensitive information in plain text in the first place.
properties (22)
post_id38,155,608
authorfr3eze
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t133029800z
categorysteemauto
json_metadata"{"app": "busy/2.4.0", "community": "busy", "tags": ["steemauto"]}"
created2018-03-12 13:30:45
last_update2018-03-12 13:30:45
depth1
children0
net_rshares0
last_payout2018-03-19 13:30:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length146
author_reputation62,134,575,174,807
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@sndbox ·
$0.02
Thanks for highlighting this @emrebeyler. The SteemAuto team really needs to implement a safer system.
๐Ÿ‘  
properties (23)
post_id38,165,774
authorsndbox
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t143125116z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "users": ["emrebeyler"], "tags": ["steemauto"]}"
created2018-03-12 14:31:24
last_update2018-03-12 14:31:24
depth1
children0
net_rshares8,265,177,687
last_payout2018-03-19 14:31:24
cashout_time1969-12-31 23:59:59
total_payout_value0.018 SBD
curator_payout_value0.005 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length102
author_reputation632,573,670,086,700
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@nristen ·
Thank you for sharing this valuable information - I will steer clear of them until I hear of a change.  On piece of advice that I have is to make sure each password is unique to each site.  I use LastPass for to help manage this which removes most of the difficulty with remembering and entering strong passwords.
๐Ÿ‘  
properties (23)
post_id38,171,453
authornristen
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t150726375z
categorysteemauto
json_metadata"{"app": "busy/2.4.0", "community": "busy", "tags": ["steemauto"]}"
created2018-03-12 15:07:27
last_update2018-03-12 15:07:27
depth1
children0
net_rshares5,658,175,988
last_payout2018-03-19 15:07:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length313
author_reputation114,815,362,149
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@mahdiyari ·
$0.28
yes,
that is right.
that was because I will remove this login system and all saved passwords.
I will use steemconnect as login system.
๐Ÿ‘  , ,
properties (23)
post_id38,187,221
authormahdiyari
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t165221716z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 16:52:21
last_update2018-03-12 16:52:21
depth1
children9
net_rshares91,950,014,446
last_payout2018-03-19 16:52:21
cashout_time1969-12-31 23:59:59
total_payout_value0.269 SBD
curator_payout_value0.011 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length134
author_reputation50,504,878,810,975
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (3)
@emrebeyler ·
Thank you @mahdiyari for the clarification. Looking forward to see the upcoming developments on Steemauto. ๐Ÿ‘
properties (22)
post_id38,194,404
authoremrebeyler
permlinkre-mahdiyari-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t174033072z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "users": ["mahdiyari"], "tags": ["steemauto"]}"
created2018-03-12 17:40:33
last_update2018-03-12 17:40:33
depth2
children1
net_rshares0
last_payout2018-03-19 17:40:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length108
author_reputation319,480,565,467,431
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@mahdiyari · (edited)
Login method changed. I hope to see a new post or edited post here:)
I'm going to remove all information(passwords and emails).
properties (22)
post_id38,233,782
authormahdiyari
permlinkre-emrebeyler-re-mahdiyari-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t223116699z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 22:31:18
last_update2018-03-12 22:32:00
depth3
children0
net_rshares0
last_payout2018-03-19 22:31:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length127
author_reputation50,504,878,810,975
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@leprechaun ·
Why when you can simply Convert the Private Posting Key to it's Public key and see if it matches the account information?  
```
# Routine returns 'owner'   if passed the master password or private owner key
#                 'active'  if passed the private active key
#                 'posting' if passed the private posting key
#                 'memo'    if passed the private memo key
#              or None otherwise

def get_login(connection, username, password):
    pk = None
    try:
        Pk = PrivateKey(password)      
        pk = Pk.pubkey
    except Exception as e:
        # Perhaps not a private key
        Pk = PasswordKey(username, password, role="owner")
        pk = Pk.get_public()
    if testnet:
        spk = format(pk, "STX")
    else:
        spk = format(pk, "STM")
    s = steem.steem.Steem(nodes=get_node_list(connection))
    account_information = s.get_account(username)
    for role in ['owner', 'active', 'posting', 'memo']:
        try:
            for key_power_pair in account_information[role]['key_auths']:
                if spk == key_power_pair[0]:
                    return role
        except:
            pass
    return None
```
properties (22)
post_id38,226,059
authorleprechaun
permlinkre-mahdiyari-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t213352438z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 21:34:18
last_update2018-03-12 21:34:18
depth2
children6
net_rshares0
last_payout2018-03-19 21:34:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length1,178
author_reputation3,043,219,887,107
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@mahdiyari ·
$0.05
Storing posting key is not secure!
๐Ÿ‘  
properties (23)
post_id38,296,014
authormahdiyari
permlinkre-leprechaun-re-mahdiyari-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180313t060545558z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-13 06:05:45
last_update2018-03-13 06:05:45
depth3
children5
net_rshares18,171,472,027
last_payout2018-03-20 06:05:45
cashout_time1969-12-31 23:59:59
total_payout_value0.042 SBD
curator_payout_value0.012 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length34
author_reputation50,504,878,810,975
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@dexterdev ·
Great article. Good job man. This is really helpful. Resteeming it
properties (22)
post_id38,187,411
authordexterdev
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t165152574z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 16:53:33
last_update2018-03-12 16:53:33
depth1
children0
net_rshares0
last_payout2018-03-19 16:53:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length66
author_reputation14,307,229,891,937
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@buy-bitcoin · (edited)
Tellin' it like it is. Good man.

### This would be a good time to change  Steemauto passwords as well as other accounts. 

Take precaution.
๐Ÿ‘  
properties (23)
post_id38,189,572
authorbuy-bitcoin
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t170719337z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 17:07:21
last_update2018-03-12 17:09:24
depth1
children0
net_rshares542,118,128
last_payout2018-03-19 17:07:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length140
author_reputation152,522,295,653
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@vanessahampton ·
Oh, my
properties (22)
post_id38,191,091
authorvanessahampton
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t171740071z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 17:17:45
last_update2018-03-12 17:17:45
depth1
children0
net_rshares0
last_payout2018-03-19 17:17:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length6
author_reputation3,362,533,862,951
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@honeylyn2330 ·
Nice blog @emrebeyler
Very big help to us
properties (22)
post_id38,199,393
authorhoneylyn2330
permlinkre-emrebeyler-2018313t2181886z
categorysteemauto
json_metadata"{"app": "esteem/1.5.1", "format": "markdown+html", "community": "esteem", "tags": ["steemauto", "steem", "security", "sndbox", "busy"]}"
created2018-03-12 18:18:21
last_update2018-03-12 18:18:21
depth1
children0
net_rshares0
last_payout2018-03-19 18:18:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length41
author_reputation0
root_title"Steemauto stores your passwords in raw format!"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@frederichs ·
thank you my friend for clarifying this a bit, really, I needed a great article, my vote for you,
properties (22)
post_id38,214,160
authorfrederichs
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t200601580z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-12 20:06:06
last_update2018-03-12 20:06:06
depth1
children0
net_rshares0
last_payout2018-03-19 20:06:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length97
author_reputation1,265,383,660,414
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@postpromoter ·
$0.06
re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t201155762z
You got a 10.20% upvote from @postpromoter courtesy of @emrebeyler!

Want to promote your posts too? Check out the [Steem Bot Tracker website](https://steembottracker.com) for more info. If you would like to support the development of @postpromoter and the bot tracker please [vote for @yabapmatt for witness!](https://v2.steemconnect.com/sign/account-witness-vote?witness=yabapmatt&approve=1)
๐Ÿ‘  
properties (23)
post_id38,214,943
authorpostpromoter
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180312t201155762z
categorysteemauto
json_metadata"{"app": "postpromoter/1.8.6"}"
created2018-03-12 20:11:57
last_update2018-03-12 20:11:57
depth1
children0
net_rshares21,725,281,607
last_payout2018-03-19 20:11:57
cashout_time1969-12-31 23:59:59
total_payout_value0.049 SBD
curator_payout_value0.014 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length394
author_reputation21,053,937,692,175
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@jdc ·
Does this mean we have to keep logging in with our active key every few hours? Because I'm not doing that.
properties (22)
post_id38,264,198
authorjdc
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180313t021426127z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-13 02:14:27
last_update2018-03-13 02:14:27
depth1
children0
net_rshares0
last_payout2018-03-20 02:14:27
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length106
author_reputation1,190,023,548,895
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@cryptohazard ·
I would also add that you need a way to *properly* score  the passwords . I usually recommend https://github.com/dropbox/zxcvbn/tree/master
properties (22)
post_id38,444,450
authorcryptohazard
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180313t225044845z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "links": ["https://github.com/dropbox/zxcvbn/tree/master"], "tags": ["steemauto"]}"
created2018-03-13 22:50:45
last_update2018-03-13 22:50:45
depth1
children0
net_rshares0
last_payout2018-03-20 22:50:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length139
author_reputation17,113,283,041,617
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@valth ·
Thanks for the warning! This is definitely worrying, but luckily I used a throwaway password there.
properties (22)
post_id41,394,608
authorvalth
permlinkre-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180331t070706086z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-31 07:07:06
last_update2018-03-31 07:07:06
depth1
children3
net_rshares0
last_payout2018-04-07 07:07:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length99
author_reputation74,131,024,130,091
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@emrebeyler ·
$0.08
This has been handled by the owner after this post. He also stated that he removed the old database and switched to SteemConnect for the authentication.
๐Ÿ‘  
properties (23)
post_id41,395,829
authoremrebeyler
permlinkre-valth-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180331t071834938z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-31 07:18:36
last_update2018-03-31 07:18:36
depth2
children2
net_rshares30,146,459,512
last_payout2018-04-07 07:18:36
cashout_time1969-12-31 23:59:59
total_payout_value0.078 SBD
curator_payout_value0.006 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length152
author_reputation319,480,565,467,431
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@valth ·
Oh, that's great! I realized it that the post was a little bit old, but I didn't expect it to have been fixed yet. Thanks for the update :)
properties (22)
post_id41,396,986
authorvalth
permlinkre-emrebeyler-re-valth-re-emrebeyler-steemauto-store-your-passwords-in-raw-format-20180331t073020132z
categorysteemauto
json_metadata"{"app": "steemit/0.1", "tags": ["steemauto"]}"
created2018-03-31 07:30:21
last_update2018-03-31 07:30:21
depth3
children1
net_rshares0
last_payout2018-04-07 07:30:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length139
author_reputation74,131,024,130,091
root_title"Steemauto stores your passwords in raw format!"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000