Rant about EOS low-security launch process

in #eos6 years ago (edited)

EOS lack of standard key generation tool and offline registration instructions this close to launch is an embarassment and a disgrace. Less than a month from the freeze, the only way to generate keys offline relies either on third party tools like this one from @nadejde that require trusting the author or involves goofing around with official nodejs libraries (a big thank you to @eosnewyork for providing this guide). So far the only known ways to register offline involves importing manually the EOS ABI in Mist or using the online MEW contract calls with a dummy private key, and signing the generated blob offline. Above trickery is far beyond the abilities of the general public and I'd be surprised if even 1% of the EOS holders generated their keys using trusted code, and registered them offline.

Key generation is the absolute base of any crypto system and underpins the entire future security model. With the current confusion around EOS registration and its near entire reliance on third party tools and instructions, for all we know many EOS registered wallets could already be compromised due to third party tools eavesdropping on keys, generating them with too little entropy or using a pseudo-random, reproductible key generation process.

As discussed in this very apropos comment in the @eosnewyork thread I linked above, we are heading toward a possible repeat of the IOTA key generation fsck up.

As a very early supporter of Dan's work, I'm deeply disappointed by the careless approach taken by EOS.

Sort:  

I'm sure Dan doesn't intend to keep it this way. Until the main net is launched, we have no idea how key generation will work but I highly doubt it'll be offline generation as even though I'm not an expert in cryptography like Dan, even I can tell that it's poor practice.

I've invested in EOS simply because I love what he's done with bitshares and steem, I see EOS as the next stage in this ongoing development and I trust he'll not screw it up like the IOTA team who have made hundreds of rookie mistakes and don't particularly know what they're doing.

I hope they're doing something about that already. They better not be so stupid to let this project ruined just because of the lack of security feature when almost all their competitors have it.

EOS is now under developing their system but EOS future is bright due to EOS application in deffrent purpose. Thanks for your valuable post .

EOSIO is having negative impact, because of this. Users are getting upset about the matter. They should work on their own, without depending on third parties.

Maybe they are working on this as more upgrades keep coming

And their something's we do after the bad had happened maybe until they find out them selves before measures are taken

Third party security dependent is not help ing the system, EOS should rectify this lapses to enable user have full access to their account.

I have some bitshares, i have a bit of steem and i do not have eos

that means from an investment standpoint i might be to late but I just cannot bring myself to buy some and then have to go through all the mess described above

on another note, i can see that you are not voting for any witnesses, what would something that would possibly convince you to do so?

and if you just forgot then please just vote for @swisswitness
steemconnect makes that really easy now
https://steemconnect.com/sign/account-witness-vote?witness=swisswitness&approve=1

@recursive you were flagged by a worthless gang of trolls, so, I gave you an upvote to counteract it! Enjoy!!

Congratulations @recursive! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 3 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Congratulations @recursive! You have completed the following achievement on the Hive blockchain and have been rewarded with new badge(s):

You received more than 21000 HP as payout for your posts and comments.
Your next payout target is 22000 HP.
The unit is Hive Power equivalent because your rewards can be split into HP and HBD

You can view your badges on your board and compare yourself to others in the Ranking
If you no longer want to receive notifications, reply to this comment with the word STOP

Check out the last post from @hivebuzz:

Hive Power Up Month - Feedback from day 10
Support the HiveBuzz project. Vote for our proposal!

Hey, just to let you know, you can auto curate using:
https://auto.vote

It's free and uses https://hive-keychain.com as the login method.

Hey king! We need you, you're a such valuable member of the HIVE community and we need your help to bring the most advanced NFT market to HIVE that will integrate all the games and offer a new level experience to the NFT traders on all our blockchain. We're running a proposal and your vote is necessary to reach the goal. Thanks in advance king!

Loading...