A Quick Guide To How Keys and Passwords Work on Steem and Steemit

in #steemit7 years ago (edited)


Introduction - Key Confusion


ThinkstockPhotos-90978047.jpg

Most new users have difficulty understanding the different keys.

One of the subjects most new users seem to have questions about is that of what the different keys on Steem/Steemit are for and how to make use of them.

I don't normally like to post about Steemit matters but this one seems to be difficult for new people to grasp.

That suggests that the current material provides an inadequate explanation for those who are new to these topics.

Indeed this is proven by the fact that several people have emailed me their owner keys when asking for help!


The 4 Keys that Steem/Steemit uses


For all intents and purposes key and password mean the same thing (however Steemit sometimes uses the term password to refer to your owner key).

Keys.png

The Permissions page.

Steem/Steemit has 4 different key types:

  1. Posting Key - this is what you use to make posts, comment and upvote/flag using your account. This is what you should use most of the time.

  2. Active Key - this allows you to interact with your wallet i.e. sending Steem/SBD etc. It also lets you change the information on your profile. Only use it when you absolutely have to (i.e. to move Steem/SBD around) and keep it offline the rest of the time.

  3. Owner Key - this is your master password. It lets you do everything, including changing to a new owner key, which will change all your other keys. You should only use it for this purpose and keep it offline at other times. You can change this by using the "password" page. Do not lose it.

  4. Memo Key - this doesn't really do anything right now but will be used to sign messages (i.e. confirm you sent them) at a future date. You don't need to use this at the present time.


Accessing your keys and password


You can see your keys on the "Permissions" page (as shown in the previous screenshot).

Screenshot 2017-06-16 14.52.28.png

Click Wallet then Permissions to see your keys.

To get there from your main blog page, click "Wallet" then click "Permissions".

Initially you will be shown the public keys - I won't go into the specifics of what these do (see quick explanation here), but in order to authorise any kind of action on your account you need to use the private key.

Depending on which one it is you can see it either by clicking or entering your owner key (master password).

(Note you cannot view the owner key for obvious reasons - what would you use to login to view it?)


Changing Your Owner Key (Master Password)


Password Page.png

The Password Page (Open in New Window to enlarge)

This is done using the "Password" page as shown (Click "Wallet" then "Password").

Note the scary messages.

The first rule of Steemit is: Do not lose your password.
The second rule of Steemit is: Do not lose your password.
The third rule of Steemit is: We cannot recover your password.
The fourth rule: If you can remember the password, it's not secure.
The fifth rule: Use only randomly-generated passwords.
The sixth rule: Do not tell anyone your password.
The seventh rule: Always backup your password.

DO NOT, whatever you do, lose your Owner Key. Without it you will lose access to your account and it is unlikely you will be able to recover it.

Keep it safe and secure. Use multiple backups. A password manager can help but you need to make sure you use it and manage it properly.


KEY POINTS!


There are some key points (pun intended) that all new users should keep in mind:

ThinkstockPhotos-507400394.jpg

Key advice.

  1. You should normally log in to Steemit using your POSTING KEY.

  2. Always keep your Owner and Active Keys offline unless and until you need them.

  3. Keep multiple types of secure backups of all your keys - a password manager can help but make sure it is properly secured and backed up.

  4. DO NOT send people your keys in email, chat or any other way. I have had multiple people email and message me their Owner Keys! If I was a criminal I could have taken over their accounts.

  5. Be careful not to accidentally cut and paste your active key into the memo area when making financial transactions (see this post).

  6. If you think you have accidentally disclosed any of your keys immediately go to the "Password" page so you can change your Owner Key. This will change all your other Keys too and you will need to record the new ones from the Permissions page.

  7. DO NOT EVER LOSE YOUR OWNER KEY!!!!!


Thank you for reading


ThinkstockPhotos-491732610.jpg




Steemithelp.net

Are you new to Steemit and Looking for Answers?

Please visit:

Steemithelp.net

A collection of guides and tutorials that cover the basics of Steem and Steemit.


Follow me Steemit & Twitter.

All uncredited images are taken from my personal Thinkstock Photography account. More information can be provided on request.


Sort:  
There are 2 pages
Pages

Moral of the story: Use your posting and active keys as opposed to being lazy and using your Owner key for everything.

And I literally changed my owner key last night as I accidentally posted mine into a chat....ugh.

Heed the advice in this post folks!

Thank you. Your explanation is neat and easy to understand, and it has cleared the mist for me about how the four keys work. It's really important for us to store our keys in safe places, especially for the owner key.

You're welcome! Yes.

Another great post added to my "steem guide" bookmarks folder on my browser.

I'm about to start creating sub-folders to keep it all organized.

Upvoted and resteemed

Thank you.

Thank you, I'm not sure how I'm going to get him to read them but there are quite a few of you who are going to educate my teenager on how to be successful here.

He started a couple of days ago.

Cool - he may already be reading them.

He's at Driver's Training right now, and I haven't told him he's not allowed to read it yet.

That's the only sure way to get him to do it. ;-)

this was a very concise and clear exposition of the relevant facts about keys and passwords. This should actually be part of a cache of related steemit user tools that newbies can access.

For that matter, judging from the keys that even long term users sent you, we could all use a reminder from time to time about the importance of keys and the dangers of treating them carelessly.

Good post!

Nice post and nice pun :)

Great article and info on knowing your steemit keys @thecryptofiend I like especially the tip on accidentally disclosing any of your keys and what to do immediately after thanks.

You're welcome:)

This post received a 20% upvote from @randowhale thanks to @kyriacos! For more information, click here!

This a very good reminder for all of us. Thank you!

You're welcome:)

Can I keep the cat, too?

Great post, steemits introduction did not cover the keys very thoroughly

I never truly understand the keys , i've use it just once for a thrird party website . just ike your name are your post .. all about crypto fields

Very useful information, I didn't know that my Steem account had so many keys! I'm going to back all of them up after this comment:)

Yes and make sure to only use the posting key for normal interactions.

Haha the one thing that terrifies me about everything blockchain is the importance of not loosing your passwords. So used to never having to remember them for anything else

That's the thing. You have to take personal responsibility. It is the price for greater freedom.

Great post. It removed my last doubts on the use of the steemit keys.
Thank you. Upvote and resteem.

this reminds me that i have to backup my keys where i can find them if need be 😉 i already use a password manager because too many passwords to remember already 🤣 good post btw, resteemed cuz info is useless if not shared

good guide, thanks for sharing!

You're welcome:)

Thanks for these tips @thecryptofiend its very helpful indeed for new and some old members...keep up the good work.

Thanks for this..please can someone enlighten me on how to upload a profile picture and also link my steem account to my facebook. Thanks

To upload a profile picture click on Settings and paste a link into where it says "PROFILE PICTURE URL". You will need to use an image hosting site like Imgur or imgsafe to get a link. Also you will need your Active key if I remember correctly in order to save it when you click "Update".

Screenshot 2017-06-16 17.07.29.png

You can enter your Facebook page address where it says "WEBSITE". I don't know of any other way to link FB to your account.

Thanks so much

You're welcome:)

Short and to the point. The site can be quite complex for a new user. Keep it up!

So can I just store the owner key?

Yes as long as you don't lose it. The only time you should ever use it is to change to a new owner key/change your other keys. Apart from that keep it offline.

I am a newbie so forgive me what may appear to be a stupid question. So when I click on "Permission" i get a list of all the keys. How exactly does one keep one or more of these 'offline'. What does this mean? Does this mean that I somehow need to delete it from the 'Permission' page after I back it up by writing it down or some other method? Thanks for the help.

Not a stupid question at all. Keeping them offline just means not using them:) . You can't remove them from the permissions page but you are the only one that can see them.

protonmail

What about it?

hi protonmail is an encrypted email acct, I post an email from PM acct 1 to a second PM acct 2 and my private key is 100% encrypted in all its locations...

That video you posted has zero relation to this post. Further whether proton mail is encrypted or not I think it is foolish to use it to send your private key.

LoL well Ok you are the one with the 47 million dollars, me I just have a thousand dollars . . .
Yep that video is just about mass murder, something probably fairly important to most people of a good conscience I think...

So what is the primary role of the private posting key? and how should it be used?

You should use it most of the time. It lets you post, comment and vote.

thanks, can a hacker steal it and use it in nefarious ways?

Well they could use it to vote for things you don't like and post rubbish but they can't take money out of your wallet or lock you out of your account.

Spamming comments is frowned upon by the community.

Continued comment spamming may result in action from the cheetah bot.

This should be required reading for all new members!

Yes - hopefully then they won't email their owner keys or post them in the chat!

Thanks for sharing this useful information....:)

Hi first of all, thank you for sharing this information it is very helpful to new users like me and I think it was a really nice post. thanks for sharing, I had a question about Key Point 2 always keep keys offline, how do you know which key is online?
thanks :)
Soy tu tio

There is no way to be sure because you can't see it. Just be sure not to save any of the more important keys in your browser.

ooooh, ok well thanks a lot, brother :)
I just saved my password to log in is that one fine ?

As long as you are using your posting key and not your owner key it should be OK.

Only the public key is used to decrypt messages/transactions,
The privately never share or transmitted,
Good cookbook 🎰

It depends on the specific encryption model being used I think but it is a simple way of thinking of it.

The key confusion about keys is that there different key for different things.
Am i confusing myself or everyone else. :-)
Nevertheless, saving a copy of this for reference.
Thanks for the info.

:)

indeed helpful for newcomers like me , keep up the good work !

thanks for sharing the post

You're welcome.

Thank you for the info buddy !

You're welcome:)

Thank you for your post, I wasn't aware of all those key before reading~

Great tips, posting explanatory and excellent to understand.

Thanks for this info! I was absolutely clueless about the keys and what they do until now. I Resteemed immediately so other newbies like me may read it.

I'm glad it helped:)

Great post!

I'd add perhaps that it is recommended that you use your Posting Key for everyday use, and instead use your Master Key only if you need to administer the account. Which should happen rarely.

Thanks for sharing!

It's in the post in 2 places. Also I think you mean owner key rather than master key.

There is a Master key and an Owner key, that are not necessarily the same. And my apologies, I must have missed it both times, lol! ^^

Not quite I think I should have been a bit more specific. The owner key acts as a "master password" which will be accepted by any of the forms - I think that is where you are getting it confused because the term "master" is used descriptively but the actual name of the key is the "owner key".

I think the master key, also sometimes called "the password", is the first key used at registration. It then can be safely forgotten as long as you store at least the owners key.

(Might be incorrect. because this is all very confusing even to senior users, but that's the way I understand it.)

That is the owner key as I understand it. If you lose it you are in trouble.

I think the master and the owner key get confused because there is very little difference.

Check these two posts.

I personally don't have any clue what my master key is anymore or whether I was even given one to begin with, but still have all the others including the owners key.

Thanks for sharing! A link to your post was included in Steem.center wiki page about Steem Key Management. Thanks and good luck again!

Thanks!

Hey great post! You made this whole private key thing clear and easy to understand. I've been wanting to experiment with steemvoter and streemian, so I can join the minnow support network, but had no idea which key to use when registering! Huge help, thanks again!

You're welcome.

very intresting n nice post keep it up dear

Thanks!

pleasure is all mine followed you and so u also , so kind of u thanks

and it will be my pleasure and a big contribution from your side if you upvote me also , it will be big achievement for me , hope for positive response .

@thecryptofiend We learn so much from you man, no body explained this to us, Amazing effort !Thank you

Beautiful post.

Have a nice day!

This is a great write up for everyone!

Thanks mate:)

Great advice my friend!!! Thank you for ALL that you do ;-}

thanks for your guides...but the cat is wonderful!

Thanks @thecryptofiend - useful reminder for the old guys and especially to her all the new Steemians. Resteemed for further Exposure

Thanks mate!

BUT what happens if I lose my Password, only joking, thank you for the information :)

You're welcome:)

Thanks for the post! Very informative!! I'm going to save this post as a bookmark to keep it as a reference :)

Thank you for taking the time to explain. more people need to know about that. I like your post I upvoted and resteem @thecryptofiend

Definitely much needed updated post on what the heck those things are. I've probably messed up on how I use these, but it was lack of knowledge. The one thing I do know, is that I got the owner key locked and copied and stored offline in several places. Thanks @thecryptofiend

I think you should be OK as long as you have the private owner key saved.

nice post

Great shout out about the different sets of Steemit keys, it is vital to keep them safe and even better making a few backups just in case, lol.

Fantastic article, sir!!

Thanks mate:)

Nice topic!

There are 2 pages
Pages