Offline Attack on Steem User Credentials by robinhood

View this thread on steempeak.com
· @robinhood ·
$7,754.81
Offline Attack on Steem User Credentials
Moments ago I changed the owner/active/posting/memo keys of ~500 Steem accounts.  

I changed their keys to Steemit's key so Steemit can allow these users to regain access via the recovery mechanism they established.  

I was able to do this because I was able to guess these account's passwords.  

I was able to guess their passwords because of what I would argue is a flaw in Steem's UI.  Specifically, it currently allows users-chosen passwords by default.  In most applications user-chosen password are not problematic.  However, they are problematic in this use-case because a scrambled form of each user's password must be stored on Steem's public blockchain meaning anyone with a copy of the blockchain can mount a large-scale offline dictionary attack to recover them.  Research as well as real-world precedent has repeatedly shown that a non-trivial fraction of users are incapable of choosing passwords resistent to offline-attack even when password complexity requirements are enforced.  

Forcing machine-generated passwords in the UI for owner/active keys would be one possible step towards mitigation.  I'm aware of the usability counter-argument to this suggestion.  However, consider that my effort expended ~1 USD of computing resources and ended up recovering the credentials of accounts with liquid assets valued in the thousands and semi-liquid assets (SP) in the tens of thousands.  Given this fact, it would be hopelessly naive to assume offline attacks will not be attempted in the future at much greater scale and by totally bad actors.

I invite others with constructive mitigation ideas to share them.

One futher point, unless explicitly invited by Steemit, I will not attempt any future white hat shenanigans.  My motivation was to alert this community to a genuine danger and do so in manner that hopefully leaves a more lasting impression than yet another "how to pick a strong password" snorefest post.

[![12345](http://media-cache-ec0.pinimg.com/736x/ff/96/13/ff96133faab0e386e5c27819638a2172.jpg)](https://www.youtube.com/watch?v=a6iW-8xPw3k)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 358 others
👎  
properties (23)
post_id132,630
authorrobinhood
permlinkoffline-attack-on-steem-user-credentials
categorysteem
json_metadata"{"links": ["http://media-cache-ec0.pinimg.com/736x/ff/96/13/ff96133faab0e386e5c27819638a2172.jpg)](https://www.youtube.com/watch?v=a6iW-8xPw3k"], "tags": ["steem", "steemit", "security", "passwords"]}"
created2016-07-19 05:56:00
last_update2016-07-19 05:56:00
depth0
children71
net_rshares130,226,634,576,617
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value5,818.194 SBD
curator_payout_value1,936.618 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length2,077
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (423)
@arhag ·
$672.94
Yup, this is exactly what I have been shouting about for weeks now and expected would eventually happen. I am happy that you are a white hat and didn't take control of the accounts for yourself to profit from.

I believe it is better to push away new users with less user friendly registration (that forces them to use a randomly generated key that they must store securely and use password managers to manage) than to bring them aboard easily only to completely piss them off when their account or funds are stolen [1]. It is our job to make it as user-friendly as possible and to provide great resources educating users how to generate and manage random high-entropy passwords. But I don't agree with compromising their security because it is "too hard" and we don't want to lose them as new users.

[1] Although the new recovery feature allows them to get their account back. Most funds are usually locked in the time-locked Steem Power, so hopefully not too much financial damage would be done by the time they recover their account. And there are plans for a user opt-in and configurable time-locked savings account to even protect their more liquid STEEM and Steem Dollar funds from being stolen by hackers assuming they recover their account in a few days.
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
post_id135,200
authorarhag
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t104218144z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 10:42:18
last_update2016-07-19 10:42:18
depth1
children14
net_rshares36,990,417,460,332
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value504.762 SBD
curator_payout_value168.181 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length1,263
author_reputation52,480,746,024,977
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (45)
@cass ·
$176.60
… we are in needs of a bug bounty program with high rewards, that people are happy to publish the flaws, instead of misusing them for the own profit in the short run! **Thank you for being honest and alarming the devs and community - and not run with the money** …! 

# Chapeau !
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
post_id147,229
authorcass
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160719t225759748z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 22:58:00
last_update2016-07-19 22:58:00
depth2
children6
net_rshares18,064,825,530,140
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value132.492 SBD
curator_payout_value44.103 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length279
author_reputation87,543,160,636,924
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (29)
@cass ·
$125.78
and tipping is always an option as well -  *thx again*!
👍  , , , , , , , , , , ,
properties (23)
post_id149,056
authorcass
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t004555546z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:45:57
last_update2016-07-20 00:45:57
depth3
children0
net_rshares14,952,715,546,515
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value94.350 SBD
curator_payout_value31.426 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length55
author_reputation87,543,160,636,924
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (12)
@cass · (edited)
$124.50
I WILL donate/contribute my rewards gotten out of my comments here @robinhood as well, and **you guys here**  should considering to do this as well...if everybody here WILL doing this i'd double the **comment** payment amount to donate out of my pockets again!
👍  , , , , , , , , , , ,
properties (23)
post_id158,511
authorcass
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t124910967z
categorysteem
json_metadata"{"users": ["robinhood"], "tags": ["steem"]}"
created2016-07-20 12:49:09
last_update2016-07-20 15:55:42
depth3
children0
net_rshares14,867,402,568,490
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value96.396 SBD
curator_payout_value28.100 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length260
author_reputation87,543,160,636,924
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (12)
@itsjoeco ·
Happy to introduce anyone to Jacob at Cobalt - best bug bounties with a specialization in cryptocurrency companies.
properties (22)
post_id164,548
authoritsjoeco
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t191400093z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 19:13:57
last_update2016-07-20 19:13:57
depth3
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length115
author_reputation3,302,850,291,836
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@hastla ·
$24.90
@cass - the largest flaw now in my opinion is that overgrowing "tag-spamming" people do. When you have for example in top 12 of "marijuana" topic just 3 related ones the platform has a massive problem.  This get worse hour by our and people tag nearly all their posts wrong.
👍  , , , ,
properties (23)
post_id165,113
authorhastla
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t194323327z
categorysteem
json_metadata"{"users": ["cass"], "tags": ["steem"]}"
created2016-07-20 19:43:27
last_update2016-07-20 19:43:27
depth3
children1
net_rshares5,753,803,506,316
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value18.682 SBD
curator_payout_value6.221 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length274
author_reputation3,557,223,159,170
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (5)
@willytrader ·
first official STEEM LOTTERY  https://steemit.com/lottery/@willytrader/first-official-steem-lottery
properties (22)
post_id171,121
authorwillytrader
permlinkre-cass-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160721t014800864z
categorysteem
json_metadata"{"links": ["https://steemit.com/lottery/@willytrader/first-official-steem-lottery"], "tags": ["steem"]}"
created2016-07-21 01:49:21
last_update2016-07-21 01:49:21
depth3
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length99
author_reputation-445,542,245,044
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@ma3 ·
$0.04
This is someting i'm really concerned about arhag, do you have any information i can use at the moment to protect myself further?
👍  
properties (23)
post_id147,977
authorma3
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160719t234313059z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 23:43:09
last_update2016-07-19 23:43:09
depth2
children3
net_rshares20,470,926,872
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.028 SBD
curator_payout_value0.007 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length129
author_reputation1,456,576,615,524
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@arhag ·
$0.65
I do actually. I just wrote [this post](https://steemit.com/steem/@arhag/can-you-remember-your-steemit-password-if-so-you-are-in-danger) about the importance of using password managers.
👍  , , ,
properties (23)
post_id149,151
authorarhag
permlinkre-ma3-re-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t005151515z
categorysteem
json_metadata"{"links": ["https://steemit.com/steem/@arhag/can-you-remember-your-steemit-password-if-so-you-are-in-danger"], "tags": ["steem"]}"
created2016-07-20 00:51:51
last_update2016-07-20 00:51:51
depth3
children2
net_rshares356,686,422,342
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.494 SBD
curator_payout_value0.160 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length185
author_reputation52,480,746,024,977
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (4)
@henchman ·
https://i.imgflip.com/17n89a.jpg
👍  
properties (23)
post_id156,611
authorhenchman
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t102505197z
categorysteem
json_metadata"{"image": ["https://i.imgflip.com/17n89a.jpg"], "tags": ["steem"]}"
created2016-07-20 10:25:00
last_update2016-07-20 10:25:00
depth2
children0
net_rshares112,645,773
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length32
author_reputation3,058,831,511
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@steemitpolitics · (edited)
hi @arhag, please check my latest post out. I wrote it to you and the other whales. Maybe you will agree with it :)
https://steemit.com/steemit/@steemitpolitics/6rqxnc-to-the-whales-get-your-head-out-of-your-ass-and-vote-good-content-up-you-are-harming-steemit
👍  
properties (23)
post_id164,794
authorsteemitpolitics
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t192711624z
categorysteem
json_metadata"{"users": ["arhag"], "links": ["https://steemit.com/steemit/@steemitpolitics/6rqxnc-to-the-whales-get-your-head-out-of-your-ass-and-vote-good-content-up-you-are-harming-steemit"], "tags": ["steem"]}"
created2016-07-20 19:27:15
last_update2016-07-20 19:38:36
depth2
children0
net_rshares1,403,787,926
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length260
author_reputation2,435,940,447,292
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@mranderson ·
Amazing work and really making a difference in how we all move forward in the world.
👍  
properties (23)
post_id168,381
authormranderson
permlinkre-arhag-re-robinhood-offline-attack-on-steem-user-credentials-20160720t223846247z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 22:38:45
last_update2016-07-20 22:38:45
depth2
children0
net_rshares2,345,159,469
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length84
author_reputation4,001,494,480,869
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@domavila ·
$0.15
This is why I proposed 2FA. I understand 2FA is hard to implement on the blockchain but as the saying goes "when there is a will there is a way". I feel very unsafe on this platform without 2FA. Please read this https://steemit.com/steemit/@domavila/two-factor-authentication-and-why-we-need-it-now
👍  , , , , ,
properties (23)
post_id135,927
authordomavila
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t114515951z
categorysteem
json_metadata"{"links": ["https://steemit.com/steemit/@domavila/two-factor-authentication-and-why-we-need-it-now"], "tags": ["steem"]}"
created2016-07-19 11:45:15
last_update2016-07-19 11:45:15
depth1
children0
net_rshares81,457,334,073
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.116 SBD
curator_payout_value0.029 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length298
author_reputation3,811,633,288,089
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (6)
@oholiab ·
$0.31
That's pretty terrifying, and it's a good job that you posted this... It hadn't occurred that *of course* hashed passwords are going to be freely available offline because in using a web UI you're used to the assumptions of a traditional web model.

Good on you (assuming you did what you said) for just reassigning back to Steemit. Sounds like we do really need 2FA or generated only passwords... It's a shame that browser tooling around SSL client certs is so user unfriendly, having a client cert as a per-browser alternative to the generated password would be a good way of removing the usability barrier. Users would obviously still have to store their password but they could use the installed client cert for day-to-day auth and just use the password for requesting new certs for new devices.
👍  
properties (23)
post_id137,053
authoroholiab
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t131338826z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 13:13:36
last_update2016-07-19 13:13:36
depth1
children0
net_rshares165,747,762,904
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.229 SBD
curator_payout_value0.076 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length799
author_reputation1,895,735,652,406
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@sigmajin · (edited)
im actually kind of suprised.  When they said that the hacker had private keys, i was thinking he could hashcat them to get passwords... but i figured with 16 characters that would take an unreasonable amount of time.  
I figured with a 16 digit password even the weakest passwords would be relatively hard to guess... though i do support 2FA
properties (22)
post_id141,166
authorsigmajin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t172939451z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 17:29:36
last_update2016-07-19 17:32:15
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length342
author_reputation35,846,309,024,528
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@sigmajin ·
TBH, i think this is a pretty shitty thing to do.  It definitely isnt ethical hacking, and one can only hope that the owners pursue legal measures if your claims are true.
I agree with your point.. but i dont think you should be fucking with other peoples money to make it.
👍  
👎  
properties (23)
post_id141,385
authorsigmajin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t174356207z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 17:43:54
last_update2016-07-19 17:43:54
depth1
children7
net_rshares-108,959,783
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length273
author_reputation35,846,309,024,528
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@robinhood ·
$135.45
Sigmajin, based on this comment and your last, I'm not sure you 100% understand the  situation.  

0. Regarding your first comment, I'm confused because if you can recover the private key you don't need the password.  Also, you are correct in assuming 16 chars can't be brute-forced attacked but it can be *dictionary* attacked.  If it was feasible to brute-force everyone would be screwed.
1. I didn't take these users money.  I re-assigned control of these user's accounts to Steemit which has a mechanism allowing them to establish new (hopefully better) credentials.
2. I'm curious what you would have regarded as more ethical in this instance?  Would doing nothing and watching these users get robbed be as ethical as merely burdening them with the  inconvience of being forced to pick a password that can't be trivially guessed?
👍  , , , , , , , , , , , ,
properties (23)
post_id142,115
authorrobinhood
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t182327900z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 18:23:30
last_update2016-07-19 18:23:30
depth2
children2
net_rshares15,583,634,124,240
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value101.616 SBD
curator_payout_value33.833 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length834
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (13)
@sigmajin · (edited)
OK, i was a little pissy bittrex is fucking with my money.
anyway 
1  yeah, i get that the private key obviates the need for the password here... my concern at the time was that after the users got their accounts back, the hacker could take the key, work their way backward to the users password, then use that password to attack other accounts.

2  SO what happens if the value of their assets decreases by 50%  while theyre messing around with password recovery?

3  You could have proved your point by contacting tptb with the password list.  Or upvoting this post.. or running some kind of script to make them all post horse pornography every few hours until they changed their password.

I know if it happened to me, id be pissed (even though i dont keep a ton of money here)... i guess im not behind it but i realize it was well intentioned.
properties (22)
post_id142,490
authorsigmajin
permlinkre-robinhood-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t184706056z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 18:47:03
last_update2016-07-19 19:04:12
depth3
children1
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length847
author_reputation35,846,309,024,528
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@robinhood ·
$0.85
Also 

4. I'm not the hacker from 2015-07-14 (I was unclear from your reply if you grasped this).  His/her attack vector was totally different.
👍  
properties (23)
post_id142,265
authorrobinhood
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t183123000z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 18:31:27
last_update2016-07-19 18:31:27
depth2
children1
net_rshares430,517,939,403
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.634 SBD
curator_payout_value0.211 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length143
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@sigmajin · (edited)
yeah, dk if you saw my post pointing it out but i think the 7-14 attack came from @goodgame...  the script he was using is still in all of his posts if its him, and the domain it was pinging (steemit.uk) was regged that day.  https://steemit.com/doyourpart/@sigmajin/um-this-guy-is-trying-to-do-something-bad-right
properties (22)
post_id142,743
authorsigmajin
permlinkre-robinhood-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t190231878z
categorysteem
json_metadata"{"links": ["https://steemit.com/doyourpart/@sigmajin/um-this-guy-is-trying-to-do-something-bad-right"], "tags": ["steem"]}"
created2016-07-19 19:02:27
last_update2016-07-19 19:02:45
depth3
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length314
author_reputation35,846,309,024,528
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@deedee ·
I'm actually shocked by this. There is really no legal distinction between "white hats" and "black hats". Nobody gave "robinhood" permission to hack 500 Steemit accounts. "robinhood", in fact, did "take the money"... since only "robinhood" now has access to these funds.
👎  
properties (23)
post_id142,738
authordeedee
permlinkre-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t190217734z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 19:02:15
last_update2016-07-19 19:02:15
depth2
children1
net_rshares-184,854,226
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length270
author_reputation2,531,240,049
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@robinhood ·
$2.25
> since only "robinhood" now has access to these funds.

Incorrect, as I stated in my post, I updated these accounts to Steemit's key (not my key) so only Steemit has access to the funds.  This fact can be verified by inspecting the blockchain.
👍  , , , , ,
properties (23)
post_id144,027
authorrobinhood
permlinkre-deedee-re-sigmajin-re-robinhood-offline-attack-on-steem-user-credentials-20160719t201405100z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 20:14:12
last_update2016-07-19 20:14:12
depth3
children0
net_rshares1,011,225,009,341
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.692 SBD
curator_payout_value0.554 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length244
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (6)
@ned ·
$0.99
robinhood, can you send me an email ned at steemit dot com
👍  , , , , , , ,
properties (23)
post_id145,450
authorned
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t212321142z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 21:23:21
last_update2016-07-19 21:23:21
depth1
children1
net_rshares520,556,982,735
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.765 SBD
curator_payout_value0.226 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length58
author_reputation94,526,930,487,415
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (8)
@robinhood ·
$0.38
Sure.  Sent you a message a moment ago.  May hit your spam folder since it just said "hi".
👍  
properties (23)
post_id146,304
authorrobinhood
permlinkre-ned-re-robinhood-offline-attack-on-steem-user-credentials-20160719t220638400z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 22:06:39
last_update2016-07-19 22:06:39
depth2
children0
net_rshares208,607,554,483
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.290 SBD
curator_payout_value0.094 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length90
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@lukestokes ·
$1.49
Upvoting for visibility (and the Spaceballs reference), but not without much conflict. More people need to understand how serious password security is and the need for a good password manager. At the same time, I don't want to condone grey hat activity.

There were other ways to handle this that would have been true white hat. You could have checked those 500~ passwords, verified them, and then contacted the Steemit team privately. I've been posting in the Slack channel about the need for a private bug bounty program like Bugcrowd for exactly that purpose. There should also be an easy to find ethical disclosure procedure.

In this case, however, was it really Steemit's fault or a PEBKEC (Problem Exists Between Keyboard and Chair)? All attempts at creating idiot proof software fail as better idiots are produced.

I hope you can work with the Steemit team in an ethical manner in the future. I know I'm coming across as judgemental here, and it's possible you actually saved a lot of people from a lot of trouble. It still just _feels_ wrong. Either way, I wouldn't want to get on your bad side. :)
👍  , , , ,
properties (23)
post_id145,898
authorlukestokes
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t214459451z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 21:45:00
last_update2016-07-19 21:45:00
depth1
children2
net_rshares711,664,755,526
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.122 SBD
curator_payout_value0.364 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length1,108
author_reputation395,063,281,398,324
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (5)
@billbutler ·
$0.29
I don't fault the OP. This is a classic scenario where you don't fully comprehend the gravity unless it happens. I also like the fact that the OP is being financially compensated for his discovery. I hired my first CTO after he rooted our mail server!
👍  
properties (23)
post_id148,819
authorbillbutler
permlinkre-lukestokes-re-robinhood-offline-attack-on-steem-user-credentials-20160720t003303825z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:33:03
last_update2016-07-20 00:33:03
depth2
children1
net_rshares161,012,470,617
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.294 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length251
author_reputation31,300,808,502,604
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@lukestokes ·
You might be right, Bill. I guess I'm just much more comfortable with white hat activities. We use BugCrowd for FoxyCart and have been very happy with the professionalism and ethics of those involved. When something is exposed (thankfully it's almost always some third party system outside of our PCI environment), it's hard not to take it very seriously. From what I've seen of the team here so far, I think they would have taken a white hat approach seriously also. But... maybe not. As I said, whether or not I like it, this approach may have saved quite a few people from even more frustration.
properties (22)
post_id149,186
authorlukestokes
permlinkre-billbutler-re-lukestokes-re-robinhood-offline-attack-on-steem-user-credentials-20160720t005339974z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:53:39
last_update2016-07-20 00:53:39
depth3
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length598
author_reputation395,063,281,398,324
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@aaseb ·
wow! so basically you hacked 500 accounts and gave the keys back to steemit!?
well good job!
👍  
properties (23)
post_id146,899
authoraaseb
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t223719968z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 22:37:24
last_update2016-07-19 22:37:24
depth1
children0
net_rshares5,253,185,686
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length92
author_reputation470,134,608,167
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@rogue91 ·
I think this is probably good to get such simple things done during the child life of a crypto less we have a dao scandal on steem in a year. lol
properties (22)
post_id147,626
authorrogue91
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160719t232223218z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-19 23:22:24
last_update2016-07-19 23:22:24
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length145
author_reputation307,452,322,299
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@cryptogee ·
$0.08
Very interesting, so is this just a problem with user-generated passwords?

Thanks
*CG*
👍  ,
properties (23)
post_id148,426
authorcryptogee
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t001003519z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:10:06
last_update2016-07-20 00:10:06
depth1
children3
net_rshares67,102,256,013
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.076 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length87
author_reputation371,535,229,097,172
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@robinhood ·
$0.68
I dug into the code for the "suggest password" option Steem provides at signup and as far as I could tell the logic there was 100% kosher.
👍  
properties (23)
post_id148,568
authorrobinhood
permlinkre-cryptogee-re-robinhood-offline-attack-on-steem-user-credentials-20160720t001847000z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:18:48
last_update2016-07-20 00:18:48
depth2
children2
net_rshares352,268,673,794
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.510 SBD
curator_payout_value0.167 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length138
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@liondani ·
what does that mean? Was it good?
properties (22)
post_id149,709
authorliondani
permlinkre-robinhood-re-cryptogee-re-robinhood-offline-attack-on-steem-user-credentials-20160720t012502032z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 01:25:03
last_update2016-07-20 01:25:03
depth3
children1
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length33
author_reputation91,903,771,336,326
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@tuck-fheman ·
$0.73
Nice job and thanks!
👍  , ,
properties (23)
post_id148,607
authortuck-fheman
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002054622z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:20:57
last_update2016-07-20 00:20:57
depth1
children0
net_rshares406,358,632,134
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.567 SBD
curator_payout_value0.160 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length20
author_reputation326,086,885,911,893
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (3)
@liondani ·
$34.66
I will upvote every White Hat hackers post that will help us secure more our platform! And I hope that will give them the motivation to continue working for our security!
👍  , , , , , , ,
properties (23)
post_id148,615
authorliondani
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002119711z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:21:18
last_update2016-07-20 00:21:18
depth1
children0
net_rshares7,061,490,562,896
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value28.624 SBD
curator_payout_value6.039 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length170
author_reputation91,903,771,336,326
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (8)
@belfordz ·
Its a cool concept, but I'm sorry, I call BS. 

I have looked at the code that handles hashing, salting and encrypting passwords before they are placed into the block chain and I can say with 99.5% certainty that you did not accomplish the hack you claim to have.

In theory it is possible, but the computational complexity of uncovering even 1 of the passwords from the blockchain would be more difficult that mining the largest amount held by any user on the block chain.

Sorry to hurt your feelings and call you out, but if you are to fool this community you are going to need to prove that you a. have the knowledge required to mount such a large scale offline attack, and b. you would have mentioned the actual difficulty of doing so.
properties (22)
post_id148,639
authorbelfordz
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t002303037z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:22:57
last_update2016-07-20 00:22:57
depth1
children1
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length740
author_reputation34,058,241,623
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@lukestokes ·
$97.91
> anyone with a copy of the blockchain can mount a large-scale offline dictionary attack to recover them. Research as well as real-world precedent has repeatedly shown that a non-trivial fraction of users are incapable of choosing passwords resistent to offline-attack even when password complexity requirements are enforced

They didn't claim to crack any hashing algorithm. A dictionary attack simply goes through a dictionary of possible passwords and tries each one until it finds a matching hash. Might want to reconsider that 0.5% chance.
👍  , , ,
properties (23)
post_id148,871
authorlukestokes
permlinkre-belfordz-re-robinhood-offline-attack-on-steem-user-credentials-20160720t003630552z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:36:30
last_update2016-07-20 00:36:30
depth2
children0
net_rshares12,986,583,202,202
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value73.434 SBD
curator_payout_value24.471 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length544
author_reputation395,063,281,398,324
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (4)
@bergy ·
Thanks, I guess?
properties (22)
post_id148,928
authorbergy
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t003904626z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 00:39:06
last_update2016-07-20 00:39:06
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length16
author_reputation4,713,389,536,157
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@williambanks ·
$0.82
I can say nothing here except thank you!  This really should be the most upvoted topic of the day.  Here's an upvote from me!
👍  
properties (23)
post_id150,424
authorwilliambanks
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t021007790z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 02:10:09
last_update2016-07-20 02:10:09
depth1
children0
net_rshares417,493,850,561
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.612 SBD
curator_payout_value0.204 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length125
author_reputation90,735,613,033,058
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@bleepcoin ·
i changed it now
properties (22)
post_id151,776
authorbleepcoin
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t035804636z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 03:58:03
last_update2016-07-20 03:58:03
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length16
author_reputation29,587,693,495,256
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@johnsmith ·
Holy crap I'm glad you guys are a lot smarter than I am.
properties (22)
post_id152,716
authorjohnsmith
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t051818954z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 05:18:15
last_update2016-07-20 05:18:15
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length56
author_reputation22,733,518,989,206
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@fyrstikken ·
$0.43
Thank for a great whitehat hack @robinhood 

People need to READ THIS AND TAKE SECURITY SERIOUSLY!!!! 

https://steemit.com/steemit/@fyrstikken/steemit-security-exchanges-and-why-by-a-guy-that-has-been-in-crypto-since-2009-new-people-read-this-now
👍  , ,
properties (23)
post_id152,873
authorfyrstikken
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t053106955z
categorysteem
json_metadata"{"users": ["robinhood"], "links": ["https://steemit.com/steemit/@fyrstikken/steemit-security-exchanges-and-why-by-a-guy-that-has-been-in-crypto-since-2009-new-people-read-this-now"], "tags": ["steem"]}"
created2016-07-20 05:31:06
last_update2016-07-20 05:31:06
depth1
children0
net_rshares229,395,502,593
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.400 SBD
curator_payout_value0.029 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length247
author_reputation377,282,504,744,699
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (3)
@skorss ·
great to see someone getting on the topic and doing something about it, this was completely necessary
properties (22)
post_id152,992
authorskorss
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t053913488z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 05:39:18
last_update2016-07-20 05:39:18
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length101
author_reputation590,352,098,179
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@papa-pepper ·
The hacker is a scumbag and should get his legs broken or worse.  Quit treating him like a Knight in Shining armor.. He is nothing but lowlife gutter scum who caused a lot of people a lot of problems.  Thou shall not steal.  OP is nothing but an attention whore.
👎  
properties (23)
post_id153,679
authorpapa-pepper
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t062859526z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 06:29:00
last_update2016-07-20 06:29:00
depth1
children0
net_rshares-339,256,336,586
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length262
author_reputation1,441,746,443,905,746
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@tosch ·
http://keepass.info/
properties (22)
post_id153,739
authortosch
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t063415807z
categorysteem
json_metadata"{"links": ["http://keepass.info/"], "tags": ["steem"]}"
created2016-07-20 06:34:15
last_update2016-07-20 06:34:15
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length20
author_reputation3,146,138,068,696
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@kingtylervvs ·
WHY DON'T WE HAVE GOOGLE AUTHENTICATORS?
👍  
properties (23)
post_id155,309
authorkingtylervvs
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t084531629z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 08:45:30
last_update2016-07-20 08:45:30
depth1
children0
net_rshares245,094,337
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length40
author_reputation356,633,571,001
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@endgame ·
Nice video lol thanks!
properties (22)
post_id157,253
authorendgame
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t111625716z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 11:16:27
last_update2016-07-20 11:16:27
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length22
author_reputation-1,049,810,980,865
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@nabilov ·
make sure everyone participates in the first steemit lottery
https://i.imgflip.com/17okmb.jpg
https://steemit.com/money/@nabilov/the-first-steem-lottery-hosted-by-member-nabilov#comments
👎  
properties (23)
post_id159,423
authornabilov
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t135302661z
categorysteem
json_metadata"{"image": ["https://i.imgflip.com/17okmb.jpg"], "tags": ["steem"]}"
created2016-07-20 13:53:06
last_update2016-07-20 13:53:06
depth1
children0
net_rshares-898,766,189,380
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length186
author_reputation2,499,066,298,306
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@neowenyuan27 ·
Steemit will grow bigger as a community. And with monetary rewards involved, we should expect and, maybe even accept people with different views and beliefs and motives.
 
From this post, it might just spell the beginning for many exciting things to happen here. Wherever exists blackhats, we just pray hard more whitehats appear. With the increasing popularity, this community will definitely grow, and perhaps its a good sign that @robinhood is here, helping us in his own ways. 

Even though, it indeed is wiser to leave the 'bad guys' to the 'cops'(devs), but i guess it doesn't suck if we have a @robinhood  around that we can trust, as this community grows. 

To the whitehats around!
properties (22)
post_id159,905
authorneowenyuan27
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t142728397z
categorysteem
json_metadata"{"users": ["robinhood"], "tags": ["steem"]}"
created2016-07-20 14:27:33
last_update2016-07-20 14:27:33
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length690
author_reputation225,597,006,884
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@geronimo ·
@robinhood : you are just awesome. I cannot think about how much the steem community and especially the developers need to thank you. You are incredible. Thanks for that.
properties (22)
post_id160,602
authorgeronimo
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t151022753z
categorysteem
json_metadata"{"users": ["robinhood"], "tags": ["steem"]}"
created2016-07-20 15:10:24
last_update2016-07-20 15:10:24
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length170
author_reputation2,921,161,415,347
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@faddat ·
Anyone have a recommended method of machine-generating a password?
properties (22)
post_id162,767
authorfaddat
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t173131296z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 17:31:30
last_update2016-07-20 17:31:30
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length66
author_reputation36,587,550,369,900
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@eric-boucher ·
Thanks a lot for the words of advice. Namaste   :)
properties (22)
post_id164,124
authoreric-boucher
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t184937006z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 18:49:36
last_update2016-07-20 18:49:36
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length50
author_reputation68,478,707,640,592
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@cyberdesire ·
The SpaceBalls is the my favorite movie :)
👍  
properties (23)
post_id164,662
authorcyberdesire
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t192002342z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 19:20:06
last_update2016-07-20 19:20:06
depth1
children0
net_rshares111,900,634
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length42
author_reputation470,134,608,167
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@conda ·
Up vote for space balls photo
properties (22)
post_id164,708
authorconda
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t192254564z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 19:22:54
last_update2016-07-20 19:22:54
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length29
author_reputation222,160,409,195
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@seanmchughart ·
Keep up the good work!!
properties (22)
post_id165,654
authorseanmchughart
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t201309489z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 20:13:09
last_update2016-07-20 20:13:09
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length23
author_reputation257,698,037,451
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@rdwn ·
hopefully leaves a more lasting impression than yet another
👍  
properties (23)
post_id165,836
authorrdwn
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t202200134z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 20:22:00
last_update2016-07-20 20:22:00
depth1
children0
net_rshares150,288,816
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length59
author_reputation-377,282,504,744
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@seelemonsonline ·
I'm glad you didn't do anything malicious with this great power. Key management when left to the general public is likely dangerous. Hopefully if they lose money once, they'll learn their lesson.
properties (22)
post_id166,080
authorseelemonsonline
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t203620348z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 20:36:18
last_update2016-07-20 20:36:18
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length195
author_reputation92,611,872,812
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@pierregi ·
Do the new 32 chars password requirement will prevent any future dictionnary attack ?
properties (22)
post_id167,493
authorpierregi
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t215549716z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 21:55:48
last_update2016-07-20 21:55:48
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length85
author_reputation11,422,936,900
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@blakemiles84 ·
$0.52
Hm. I vote that you continue to do this and make posts about how you did it, and what recommendations you made. 

I promise I will upvote you every time I see it :P 

You're the first white hat I've seeing doing these sorts of white hat things in crypto since I got in the game a year ago!
👍  
properties (23)
post_id167,747
authorblakemiles84
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160720t220711091z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-20 22:07:12
last_update2016-07-20 22:07:12
depth1
children0
net_rshares273,929,931,739
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.516 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length289
author_reputation51,813,680,698,502
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@theemperor ·
Look at you, so young and carefree :-)
properties (22)
post_id172,195
authortheemperor
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t030851132z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-21 03:11:03
last_update2016-07-21 03:11:03
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length38
author_reputation8,731,947,403
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@sharingtheworld ·
Hopefully steemit will realize this is something of HIGH relevance and importance, since most of the people don't know how to pick passwords (and most of those also use the same password for many identities: mail, facebook, and more). Thanks for your post, very appreciated!
👍  
properties (23)
post_id172,653
authorsharingtheworld
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t034639588z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-21 03:46:39
last_update2016-07-21 03:46:39
depth1
children0
net_rshares102,101,603
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length274
author_reputation249,268,078,932
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@kingscrown ·
thats a both sided sword. users either wont be able to registr or will loose keys and loose money anyways.

the only way i see is 2FA, still complex but most frienldy from all of this
👍  ,
properties (23)
post_id172,929
authorkingscrown
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t041129960z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-21 04:11:30
last_update2016-07-21 04:11:30
depth1
children0
net_rshares9,421,624,673
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length183
author_reputation1,990,164,104,714,661
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@dony91 ·
Amazing work and really making a difference in how we all move forward in the world.
properties (22)
post_id173,578
authordony91
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t051123372z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-21 05:11:24
last_update2016-07-21 05:11:24
depth1
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length84
author_reputation3,379,783,558
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@nioctib ·
upvote back the ones that upvote you
👍  
properties (23)
post_id175,657
authornioctib
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160721t083545013z
categorysteem
json_metadata"{"tags": ["steem"]}"
created2016-07-21 08:35:45
last_update2016-07-21 08:35:45
depth1
children0
net_rshares23,648,397
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length36
author_reputation85,113,803,820
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@liondani · (edited)
$1.41
can you get in touch with me on the slack channel?
(my name there is also liondani)

It is about a steemit user they "lost"  his owner key and needs desperately help @tonyson (lost owner key) now he posts under his new account @hien-tran read his post about the "hack" https://steemit.com/steemit/@hien-tran/i-wonder-if-you-could-help-me-with-my-account

co-founder of steemit @ned encouraged him to get in touch with you and that was a great idea in my opinion (I don't know if the reached already to you,his English are poor) I will appreciate it very much if you helped him "recover" his keys.... It is obvious that the funds he has lost are significant for him (he lives with his little Son in Vietnam)....  I can Imagine it will change his life if he can have access to his funds! Thanks in advance and please make a post about it so we can tip you for helping a dedicated community member. Thanks
👍  
properties (23)
post_id215,028
authorliondani
permlinkre-robinhood-offline-attack-on-steem-user-credentials-20160723t132937748z
categorysteem
json_metadata"{"users": ["tonyson", "hien-tran", "ned"], "links": ["https://steemit.com/steemit/@hien-tran/i-wonder-if-you-could-help-me-with-my-account"], "tags": ["steem"]}"
created2016-07-23 13:29:39
last_update2016-07-23 13:31:54
depth1
children1
net_rshares916,741,513,168
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value1.412 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length902
author_reputation91,903,771,336,326
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@robinhood ·
Sorry but I can't help this user - I checked my logs and @tonyson was not one of the accounts that I updated.  

The accounts I updated had their  keys changed to either `STM7kyb6WK6Sg9Eu4uu7WGqjYdqJzdBeKEWVDaDEKsgvhvESJZ1vM` or `STM65wH1LZ7BfSHcK69SShnqCAH5xdoSZpGkUjmzHJ5GCuxEK9V5G` which are the owner keys for @steemit and @steemit3 respectively.
properties (22)
post_id222,075
authorrobinhood
permlinkre-liondani-re-robinhood-offline-attack-on-steem-user-credentials-20160723t212823000z
categorysteem
json_metadata"{"users": ["tonyson", "steemit", "steemit3"], "tags": ["steem"]}"
created2016-07-23 21:28:03
last_update2016-07-23 21:28:03
depth2
children0
net_rshares0
last_payout2016-08-23 13:10:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length350
author_reputation2,616,843,664,428
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@steemitboard ·
Congratulations @robinhood! You received a personal award!

<table><tr><td>https://steemitimages.com/70x70/http://steemitboard.com/@robinhood/birthday3.png</td><td>Happy Birthday! - You are on the Steem blockchain for 3 years!</td></tr></table>

<sub>_You can view [your badges on your Steem Board](https://steemitboard.com/@robinhood) and compare to others on the [Steem Ranking](https://steemitboard.com/ranking/index.php?name=robinhood)_</sub>


###### [Vote for @Steemitboard as a witness](https://v2.steemconnect.com/sign/account-witness-vote?witness=steemitboard&approve=1) to get one more award and increased upvotes!
properties (22)
post_id78,103,242
authorsteemitboard
permlinksteemitboard-notify-robinhood-20190719t040656000z
categorysteem
json_metadata{"image":["https:\/\/steemitboard.com\/img\/notify.png"]}
created2019-07-19 04:06:57
last_update2019-07-19 04:06:57
depth1
children0
net_rshares0
last_payout2019-07-26 04:06:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length624
author_reputation38,705,954,145,809
root_title"Offline Attack on Steem User Credentials"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000