PSA: Check Your Account Authorities; NOW

in #hive4 years ago (edited)

Now we have all happily moved over to Hive, there are some things we need to be aware of given Hive was a snapshotted hard fork of Steem. Another Hivean @engrave is making everyone aware of their recovery account being set to Steem, something else you should be aware of as a result of the move.

Something people might not realise is account authorities have also transferred over. Not all applications moved to Hive, some dApp owners have decided to stick with Steem and support Justin Sun's hostile, childish and dangerous behaviour. I had dTube as an app and another fundition both with posting authority.

If any of these dApp owners align themselves with Justin and attempt to do anything malicious in exchange for a bribe delegation/payoff, it could be disastrous for your Hive account.

The easiest way to see what accounts have authority on your account is through the Peakd interface. Go to your profile and then click "actions" then "Keys & Permissions"

Screen Shot 20200406 at 12.26.52 pm.png

Now click the "AUTHORITIES" tab:

Screen Shot 20200406 at 12.20.11 pm.png

I have a few test applications of my own in here, but also services like busy.app which you definitely want to remove. My advice would be to revoke permissions for any Steem apps and for those that moved to Hive, provide the permissions to them again. Most of the apps with permissions I don't even use any more.

Sort:  

Along with the Authorities you have to check if the Recovery Account is Steem or not. In my case it was Steem and when I got a notification from @engrave to change it, I have initiated the process.

I have picked your post for my daily hive voting initiative, Keep it up and Hive On!!

I completely agree the best plan is likely to remove all permissions. When you reopen that application then you can assign authority again so there's little lost to removing them all.

DLive.app would likely also be directly owned by Justin now or at the very least likely subservient to him. If you see anyone with this permission then I would highly recommend to them that they remove that permission first and foremost.

Thanks for this! great reminder, and while we're revoking old auths, take a minute to change the recovery account!

Which recovery accounts are safe?

I don't even know what to change it to.

It can be any account, right? Could I just make another account and make that the recovery for my main?

thanks for the reminder!!

This may or may not be paranoid...but better safe than spamming.

I would trust nothing affiliated with Steem right now. In my case, I only had granted posting authority, but others might have granted more serious permissions besides posting. Definitely better safe than sorry.

Good point.

I removed all mine just in case.

Like you, I only had posting authority.

I don't really know what to expect with this whole thing. I keep thinking that these things that he's doing are going to tank the price of Steem...but normal people are on places like Facebook, so they aren't as affected as many that are more political in the community.

Even some of those that firmly believe in crypto may continue to use Steem to try to make money, but just go into constant power down. Or just hope that maybe this crap will only be short lived.

Thank you for sharing, I am now revoking all authorized app connected my hive account.

Great post this kind of information is essential right now!