IMPORTANT !!! Vulnerability in password protection for accounts by smi

View this thread on steempeak.com
· @smi · (edited)
$3.56
IMPORTANT !!! Vulnerability in password protection for accounts
It is necessary 30-day notice is required on the steemit.com website when the recovery-account is changed, for example, the red text in the profile "your recovery-account  has been changed, if it was not you, then your password was compromised, change the password and change the recovery-account"

I think it's not difficult to do, do not even need to edit the blockchain.

Because if an attacker steals your password, he will change your recovery-account. You will not know about it. After 30 days, the attacker will steal the account. And you can never restore it. It's worse than on facebook.

I have already told golos.io about this vulnerability and it will be fixed.
I apologize for my bad English, my telegram `@dikanevn`
http://elizabethcorreia.com/newsite/wp-content/uploads/2016/12/Vulnerability-.jpg

@abit @furion I do not know who else to note
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 53 others
properties (23)
post_id2,141,034
authorsmi
permlinkimportant-vulnerability-in-password-protection-for-accounts
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "format": "markdown", "users": ["abit", "furion"], "image": ["http://elizabethcorreia.com/newsite/wp-content/uploads/2016/12/Vulnerability-.jpg"], "tags": ["vulnerability", "steem", "steemit", "security"]}"
created2017-03-13 20:54:15
last_update2017-03-13 21:10:00
depth0
children8
net_rshares9,008,641,488,950
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value2.749 SBD
curator_payout_value0.812 SBD
pending_payout_value0.000 SBD
promoted0.001 SBD
body_length857
author_reputation427,672,289,026
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (117)
@abit ·
$0.02
Good point.
👍  , , , , ,
👎  
properties (23)
post_id2,141,595
authorabit
permlinkre-smi-important-vulnerability-in-password-protection-for-accounts-20170313t221033371z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-13 22:11:36
last_update2017-03-13 22:11:36
depth1
children1
net_rshares183,790,440,461
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.021 SBD
curator_payout_value0.001 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length11
author_reputation111,629,191,115,088
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (7)
@jacobtothe · (edited)
What do you know. There is an active user behind the flags.

Would you be willing to un-flag my posts please?
👍  ,
properties (23)
post_id2,141,765
authorjacobtothe
permlinkre-abit-re-smi-important-vulnerability-in-password-protection-for-accounts-20170313t223450423z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-13 22:34:54
last_update2017-03-13 23:00:15
depth2
children0
net_rshares376,139,834
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length109
author_reputation124,292,362,915,131
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@furion · (edited)
afaik, there is an email notification service in development that will address this and other cases.

Thank you for bringing it up.
👍  
properties (23)
post_id2,141,688
authorfurion
permlinkre-smi-important-vulnerability-in-password-protection-for-accounts-20170313t222508750z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-13 22:25:09
last_update2017-03-13 22:27:42
depth1
children5
net_rshares161,484,243
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length131
author_reputation116,591,440,117,983
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@hanshotfirst ·
Hi. I am not sure how to tell if there is a problem. I went to "stolen account recovery". If all is well, what message will I see there?

Thank you
👍  ,
properties (23)
post_id2,141,715
authorhanshotfirst
permlinkre-furion-re-smi-important-vulnerability-in-password-protection-for-accounts-20170313t222852796z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-13 22:28:51
last_update2017-03-13 22:28:51
depth2
children1
net_rshares340,757,731
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length147
author_reputation503,758,308,712,084
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (2)
@smi ·
Your Recovery account	- steem. All is well. https://steemd.com/@hanshotfirst
properties (22)
post_id2,141,772
authorsmi
permlinkre-hanshotfirst-re-furion-re-smi-important-vulnerability-in-password-protection-for-accounts-20170313t223612657z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "links": ["https://steemd.com/@hanshotfirst"], "tags": ["vulnerability"]}"
created2017-03-13 22:36:12
last_update2017-03-13 22:36:12
depth3
children0
net_rshares0
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length76
author_reputation427,672,289,026
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@pfunk ·
A message/alert on Steemit itself, in addition to an email, would be a good measure. I think a lot of people use application-specific email addresses to register on Steemit and probably don't check them often or at all.
👍  
properties (23)
post_id2,143,619
authorpfunk
permlinkre-furion-re-smi-important-vulnerability-in-password-protection-for-accounts-20170314t042721713z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-14 04:27:24
last_update2017-03-14 04:27:24
depth2
children2
net_rshares161,484,243
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length219
author_reputation208,395,764,935,287
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (1)
@furion ·
Good point.
properties (22)
post_id2,144,528
authorfurion
permlinkre-pfunk-re-furion-re-smi-important-vulnerability-in-password-protection-for-accounts-20170314t081718981z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-14 08:17:18
last_update2017-03-14 08:17:18
depth3
children0
net_rshares0
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length11
author_reputation116,591,440,117,983
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@renzoarg ·
E-mail is an already archaic technology. What about people that used disposable e-mails? (It turns out that cryptoenthusiasts are also fanatics of never disclosing personal data to anyone).

Perhaps using a signed message from another key could be used (a configurable bitcoin wallet, perhaps?)
<blockquote>To change (whatever), please sign this message with (BTC address; that should also require a signed message to be changed):<br />
<blockquote>"Change the data of my account: TIMESTAMP"</blockquote></blockquote>
properties (22)
post_id2,151,770
authorrenzoarg
permlinkre-pfunk-re-furion-re-smi-important-vulnerability-in-password-protection-for-accounts-20170315t071601388z
categoryvulnerability
json_metadata"{"app": "steemit/0.1", "tags": ["vulnerability"]}"
created2017-03-15 07:16:03
last_update2017-03-15 07:16:03
depth3
children0
net_rshares0
last_payout2017-04-14 04:03:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length517
author_reputation62,934,514,884,081
root_title"IMPORTANT !!! Vulnerability in password protection for accounts"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000