RE: How are you login in? by lemony-cricket

View this thread on steempeak.com

Viewing a response to: @meno/how-are-you-login-in

· @lemony-cricket ·
$0.05
This is really important, but why should we have to evangelise this to fellow Steemians? Steemit Inc is actually being **negligent** on this by providing a loaded footgun to users.

When you design a user experience, you should design it in a way that discourages insecure practices. There is a proverb that goes "you can lead a horse to water, but you can't make it drink." A corollary is, "you can't prevent a suicidal horse from dehydrating itself, but you _can_ make it wait by  the river until it dies."

The fact that the Condenser application even _allows_ logging in with the master password is negligent as hell. When generating their accounts, new users should be instructed to write their master passwords down and _never_ use them again... and if they try, _it shouldn't work._ Extra points for forcing them through the password reset workflow after detecting the activity.

Crypto can't go mainstream until we make the necessary security practices understandable to Average Joe. We need to expect as little of Joe as possible. We need to assume that he's not only stupid, but _actively_ acting against his own interests, because social engineering makes that not only possible, but probable; not only probable, but **inevitable**. 

Then, we need to do what we can to empower him (in a manner as _brain-numbingly simple as possible_) to protect himself from himself.

I may make this into a post later. Without cooperation from Steemit and a massive security awareness campaign, an extremely large portion of the Steem userbase, possibly even a majority, is headed for complete disaster. **We are one keylogger epidemic away from a mass extinction event.**
👍  ,
properties (23)
post_id62,292,590
authorlemony-cricket
permlinkre-meno-how-are-you-login-in-20180912t204833352z
categorysteem
json_metadata{"app":"steemit\/0.1","tags":["steem"]}
created2018-09-12 20:48:36
last_update2018-09-12 20:48:36
depth1
children0
net_rshares50,328,504,441
last_payout2018-09-19 20:48:36
cashout_time1969-12-31 23:59:59
total_payout_value0.039 SBD
curator_payout_value0.012 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length1,669
author_reputation12,334,203,545,676
root_title"How are you login in?"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)