WARNING: If you voted on steemengineteam post change your keys immediately

in #security4 years ago (edited)

This has nothing to do with @aggroed’s Steem Engine but there is an account called “steemengineteam” that has posting keys or access to other dapps posting authority for thousands of users.

If you see your vote listed on this post and you did not do it change your keys immediately until we figure out where the leak is.

https://steemit.com/ireland/@steemengineteam/ireland-its-time-to-hop-aboard-the-steemengine-2019-10-19

Will post updates as figure them out.

Take this time to review your authorizations and remove what is no longer needed.

Sort:  

Note: changing your keys might not be enough if you have authorized apps to use your account. You must revoke the app in order to keep them from using your vote.

https://beta.steemconnect.com/auths

Thanks for bringing that up. Right now it is unsure if they have keys or using a posting authority.

It doesn’t appear they have their own authority and are either using someone else’s they has access to or more likely using actual posting keys farmed via an app or accidentally leaked.

They don't use steemconnect. I signed up to check and you have to enter your posting key onto the side. It's probably saved into their own DB. So everyone who is affected by these fuckers should change his/her keys asap.

Maybe not related to this case but it's always good to review what apps are authorized to your account.

This app is not listed there.


Please excuse the editing.
In this app, the private key was saved directly on the website :-(

good idea just to review this in general. i have granted access to a ton of apps that arent even valid anymore. thats ending. tx

Good point....just revoked a bunch

A list of accounts that have voted for @steemengineteam

https://hackmd.io/BHJJ32OVQQyxf9K8MTzcbQ

Might be quicker to check than logging on to alt accounts. (Ctrl+F to search)

Thanks for the heads-up.

Thanks for putting that list together

Glad it is of use :) I didn't fancy logging into 10 alts to see if they'd voted somewhere!

Thanks. Unfortunately, I'm on the list.

If you choose to change your keys, which i think is being advised, don't forget to make an offline copy.

Already done. It's on files on USB and printed out. :-)
Thanks so much for your help on this.

I am on your list and have changed my password, but cannot find a vote for that post thru steemworld.org or https://steemd.com/ireland/@steemengineteam/ireland-its-time-to-hop-aboard-the-steemengine-2019-10-19

How did you get the names on your list?

I used @steemsql and checked every vote to the account, not just the post above.

Thanks for the reply and for using your access to SteemSQL to run the query. Do you know of another way I could look for the posts my account voted for?

There used to be a couple of places but they seem not to be running now.

same here @mytechtrail. Via Asher's link I am on the list of voters, but on steemworld and steemd, my name didnt show up

For Vienna, i downvoted it manually earlier

And for the 3rd link you gave, it was manually too

What am talking about is the Ireland post where my name is listed as voter on your list, yet am not on steemworld and steemd for that Ireland post. So thats the odd one.

Then you must be in the clear :)

The list was all votes on the account, with number of votes next to each account.

Apologies for the confusion.

Does this mean that those who are included have been infected?

I would change your keys to be safe.

Don't forget to back them up.

Phew!! Not on the list...
Thank you :)

Thanks for list @abh123454, helped to do quick check.

Big thanks to @themarkymark for head up on this.

My name is on that list but I don't see any vote going out from my account to that post in, I just checked the last 3 days using steemworld. The only votes are the ones I just did manually (4% and then back to 0%). Why is my username on that list if no vote came out from my account? @abh12345?

Edit: I think I know why my account is on that list, because I voted them in the past. But I haven't vote in their posts in months perhaps even more than a year.

Yes that is the reason and you have likely changed your keys and/or removed authority so should be good.

Thank you! !BEER



Hey @abh12345, here is a little bit of BEER for you. Enjoy it!

Freaky stuff I tell ya. That list is long.

Posted using Partiko Android

Realized how little I use steemconnect now due to steemkeychain. Time to revoke most of the apps.

.

I saw that but it is obviously storing keys as it used votes from people who have not logged in a long time.

I didn't sign up to autovote for them...

.

I'm not linked to their Steem account - just their official steem-engine.com site. I'm not autovoting them (I double checked.) It would also appear - looking at the Steem account mentioned above - that these people are trying to do a serious phishing scam.

Not trying to be argumentative, just trying to help those who are trying to figure out the leak.

.

I didn't think so.
But your previous comment was very confusing to me then. I haven't linked an account with them...

I agree. It isn't a leak... it's their business model of defaulted autocuration vote trading.

Posted using Partiko Android

I'm going to share this post in the neoxian discord. Thanks for the heads up. Luckily my vote wasn't used.

who was that guy who screwed over CC? gotta wonder if he had a few alts...

ali-h

yah that shtcnt as cope would say...

Seems like upvotes are mostly done with the users of this application, directly with the users' keys. Regarding the app accounts, here are the most common apps authorized amongst upvoters (2810)

[('busy.app', 1199), 
('steemauto', 727),
 ('dtube.app', 688), 
('steem.app', 615),
 ('dmania.app', 552), 
('dlive.app', 530), 
('bottracker.app', 441), 
('steemhunt.com', 358), 
('partiko-steemcon', 350), 
('utopian.app', 289)]

This information itself doesn't point anything exactly, though. I was curious, here is the data for others also.

okay - the only one of those I use is SteemAuto. I just checked that one too (changing keys, etc, with SteemConnect as well...) I didn't have any unauthorized autovotes.

Thank you for ggd warning @themarkymark

Time to create a steem police force

Why that?! We care for each other, do we? Anything more then this eventually gets worse, don't you think?

All right!

Thanks Mark!

Thankfully I am not on this list, but whats the best way of changing your keys?

Change password from Steemit.com and it will change all your keys.

Luckily I am not affected by this, but thanks for letting people know.

I hope that no big harm comes out of this, and everyone gets to go on about their doings without having to worry much.

For everyone not knowing how to revoke posting authority of an app or changing ur master key here :)

Resteem. Thank you @themarkymark, this is important for everyone!

So 3000 users need to change keys?

I think there was 2850 or so votes. They probably have a lot of their own accounts. Many are probably dead at this point. But I would say a lot are voting without permission.

Short tip to find out if you are on the list, go to: https://steemd.com/ireland/@steemengineteam/ireland-its-time-to-hop-aboard-the-steemengine-2019-10-19

image.png

Then click on "vote details" - so you can use Ctrl-F to search for your Acc.


Many thanks for the information @themarkymark. Is it already known whether

https://steemengine.net
is the bad guy?

I have changed my password, but could not find a vote thru steemworld.org or https://steemd.com/ireland/@steemengineteam/ireland-its-time-to-hop-aboard-the-steemengine-2019-10-19

I removed auths from most steemconnect apps, but one SCOTAUTO does not trig in my memory.

Hope you are able to find that leak if that is what is going on.

I find it interesting that they specifically only wanted posting, not active key.

Thanks for the info. That deserves a witness vote.

Thanks for the heads up

Thank you for the heads-up
Not on the list but have shared it with the Mamas group

Luckily, my vote is not listed, but I am experiencing a similar issue related to @shadowbot website.

Even though there is no authorization on steemconnect related to them and even though I have reset my keys several times, they still have access (posting) to my account. I already tried to contact them, but got no response and the setting on their website that supposedly would allow the removal of my account is broken. Other people seem to be experiencing the same issue.

Does anyone know how I can solve this problem?

@themarkymark, thank you for heads up! Another reminder of why I voted for you as a witness. 👍

Looks like I have voted for that account since my vote was on that list. I revoked all the posting keys on third party apps. But it is not good for the ecosystem. I do not use steemconnect.com anyway - prefer the Steemkeychain extension myself.

Maybe there is a chance to put an extra field on blockchain, when the third party does something on behalf of a user. That would make it easier for all of us to find the bad actors who harm the system.

steem-auths

Here is an example of what I mean. I took a real transaction and changed the data to better illustrate the idea.

What do you think abut it?

I hope my name is not in there 😶😕😕😕📃✏ can some one say it... there are more then 2000 names.

Yours is definately not there dude

Thax :) ... now I feel more good :)

Lol @foxkoit. The names are in alphabetical order so it shouldn't take you a minute to see if yours is on there or not. That said let me check it out for you.

!BEER
for @themarkymark



Hey @themarkymark, here is a little bit of BEER for you. Enjoy it!

@superheroes is also in on this scam it appears

I was a victim of this. I have since changed my password and keys.
My guess is that is was some form of "Upvote Bank" or Steem Auto that got hacked because according to Steemworld.org for that account, most of the upvotes were $0.00 and 100% but some were like 77% or 10% or whatever people had set their amounts to.

You know that saying that bad things happen to good people? I guess I'm terrible because my name is not on there. Good peeps like @slobberchops are on the list though, I hope he sees this thread and rectify that situation.

Posted using Partiko Android

Thanks, I was wondering since a while!

I am a victem of this. Just finding out today. Awful.

Now this.....kill me
C6105F76-9702-4D62-89EE-355AF7868EDD.jpeg

I hope someone can help @jazzresin out. They are trying to stop their account being abused on both blockchains. Is changing keys enough or do authorities need to be revoked too? I think @hivewatchers should stop the flagging as they have made their point.

@themarkymark, is there a way to revoke Steem authorities from the web without Keychain? He's using an iPad. I'm just trying to help sort this out, but it's gone beyond my knowledge.

There are hundreds of accounts affected by this issue, but most have been abandoned.

@jazzresin

You would need to come to our Discord to talk about it, please:
https://discord.gg/yuC7GJpw

Has anyone done a post on how to effectively disconnect the spammers from an account? There is obviously a need for that information. When people are trying to do good it's better to inform than punish.

We need more effort to actually remove rewards from the actual spammers. Some of the big trolls are actually voting them up. Doesn't look like they are using their 'botnet' for now, but then that probably didn't give them much anyway.

Sorry. Have been moving belongings into storage and am just now seeing this. I will look it up on discord. The link doesnt seem to work.

So yeah this is a bloody headache

C8428C3E-8EFD-4279-AB3B-24BDC0A50E58.jpeg

FB2489A6-A843-4064-B891-8A9B0AF8E7D9.jpeg

Should only need account recovery if you don't have master key. Changing keys is done on hive.blog or peakd. May be possible to do with a Python script. Sorry, but that is the limit of my knowledge.

Loading...

Maaaan. I dont know who to trust in this world.

Doesnt matter.
Matter is mostly empty space.

I dont think i should trust discord hivewatcher at all.

Your choice. Should you trust me?

HW have good intentions, but their people skills can be lacking. They are volunteers working under pressure. They get a lot of attacks from people. There are other channels such as the main Hive one that may be more helpful.

And someone claimed that Steem is going to be boring.

Pfft.

All kinds of crazy stuff is popping up. Thanks for the warning, glad I'm not on the list.