You are viewing a single comment's thread from:

RE: I'm Back!!! How my Account Got Stolen, How to Avoid Having This Happen To You, & How To Fix It!

You do only have 30 days to recover your account, but yeah I'm pretty certain you need to change your password too... it won't count as "recent" if it's past 30 days old, via the links I put in my post. And if it doesn't count as recent, how I understand it, is that the blockchain won't have anything to associate with your authority and ownership with the account. I'm not an expert, but that's how I understand it. :)

Sort:  

I'm also curious about the 30 days so I actually dug into the steem code and found this:

Being able to satisfy an owner authority that was used in the past 30 days is sufficient to prove past ownership.

It sounds like you need to just login every 30 days, not necessarily change the password, but it's still a little ambiguous. This is the best authority I could find so if anyone more knowledgable sees this, please comment and help us all to understand!

I by no means am a SteemIt expert, I'm still a minnow, so if I did have it wrong by all means someone correct me. This is how I understand it, because of a steemit post by @someguy123 that reads:

"The important thing is the recent password.
The STEEM blockchain knows the history of your account, and every owner key that has ever been used for it. When you enter your recent password, it uses that to generate an owner key that can match up to a previous owner public key on the account. Without that password, the trustee cannot do a thing...Small note: The "old owner key" has to be recent, which as far as I'm aware means active within the past 30 days (someone please correct me if I'm wrong)"
Read his full post here

Again, this is just how I understand it. After this I am going to change my password recently to prevent this, just to be safe.

Oh, I guess it does say "active" within the last 30 days... so looking into the logistics of what that means might be helpful.

.

I think it's insane that there are just bots trolling every post just on the off chance that someone accidentally posts a key. Seriously how big of a douche do you have to be to put time into programming that?

I KNOW! It's absolutely crazy!! Clever, but fucked up!

Where there is financial gain, people will look for opportunity to take advantage of a quick mistake it seems. It must happen often enough for it to worthwhile to have a process to harvest it. Maybe a future feature of Steemit is to do a syntaxes check like the bot is doing and warn the poster to confirm before making the post to mitigate the oops scenario?

@jeftek, that is a really fantastic idea! Have you ever logged in through minnowsupport steem -- mspsteem.com? It's a platform that looks and functions exactly like this steemit does, saves all your info, and is run by the minnow support project. I think they actually do have a feature similar to what you are talking about.. because I will tell you a secret.. when I logged in through there and made a post a few weeks ago I accidently did copy & paste my password, and it wouldn't let me make the post. A notice popped up that said "you are attempting to publish your master password and we don't allow that".