Power Down Started πŸ™ˆ You can take a horse to water but can't make it drink....Time to embrace the new style πŸ˜‰

in #witness β€’ 4 years ago

458566.jpg

It had to come, no matter how much you put in it's never enough. Dropped five Witness places in one day while investing in the servers to run my own full RPC Hive api node, I was holding out until HF24 passed to officially get it passed off because I know the top brass are busy making Hive awesome.

Don't leave us @c0ff33a

Ha! Totally got you there didn't I? The needs of the many far outweigh the belligerence of the few - so this Power Down is actually what I call Security Protocol 101

Wait, what's Security Protocol 101 it sounds awesome?

To be honest I made it up, but it does sound like something the Agents of Shield would come up with - and I've been watching a ton of that lately. To be fair the foundation of the concept is entirely down to @guiltyparties, I know he helped out one of our biggest and most active Hive Whales when he had issues with his keys and the idea stuck in the back of my mind.

So come on, spill the Beans on Security Protocol 101

Oh, you asked for it......

IMG_5909.JPG

Much coffee beans are being spilled. So after three and a half years of Blockchain I have accumulated a modest stake in Hive Tokens, but it also concerns me because in all that time I never changed the account keys and actively use the account @c0ff33a on multiple front ends, with many dapps, for my Witness and it generally means my keys are thrown around all over - and it only takes one mistake to paste a key into a phishing scam.

Just change your keys then Dumbo -_-

Well I did think long and hard over that, but it has two main problems

  1. Over those three and a half years the dapps, services and my Witness server amount to a huge mass that if I changed my account keys I would have to update - it would be a massive and tedious amount of time fixing every service that broke because I changed my keys - and let's not forget I haven't actually got a problem right now - they are not leaked after three and a half years.

  2. Changing the keys for @c0ff33a does not really solve anything - because I am active with this account, I post and comment on multiple front ends, log into many many dapps - new keys are just going to be used as many times as the old ones - and every time you use a key it's a risk. Phishers are very cunning, they can make a website look exactly like a legit one and only have a character or two in the domain different - it's way too easy to click a link and see a Hive Signer pop up and just throw your keys in. If you use a password storage site like lastpass.com, Apple Safari Passwords or Hive Keychain then you are a little bit safer because they will not autofill your password on an unknown domain.

So what is Security Protocol 101

In it's simplest form I created a cold storage account for my Hive Tokens using my own resource credits, once you stake enough Hive Tokens you can use your resource credits to claim an account ticket - when you claim a ticket you don't have to immediately create an account with it - you can just claim a ticket every day or a few a day even and store them until you need them. When you create an account yourself then you have all the keys for that account, and also you become it's Recovery Account - which makes it easy to reclaim the account if it's keys get exposed (even though they should not - because the whole idea of an cold storage account is you rarely use it)

So you are powering down but are not powering down? I don't even understand??

Yes I'm powering down, but I have set an outgoing withdraw route to my new cold storage account that will receive the Power Down in Vests - staked Hive Tokens. As it grows it's own staked Hive Power I will delegate it back to @c0ff33a - so effectively my active account will be just the same for Staked Hive Power the only difference is it will eventually not hold the Hive Tokens my cold wallet will making them more secure.

Screenshot 20200615 at 21.56.29.png

I do not have a massive investment in Hive, but this is sound advice for any investor - when your tokens are stored in an account you use all the time then there is always a risk. Every time you use your keys to access something it adds the potential for your account to be hacked.

Is Security Protocol 101 right for you? Who knows, it depends on the value of your staked Hive Tokens, how much you use dapps, how much risk you like to take and if you are happy with all your eggs in one basket. The concept however is entirely @guiltyparties

Rewards from this post are entirely set to Donate to Hive Fund to support the growth and development of the Hive Blockchain.

Active HIVE Witness alongside @derangedvisions, if you appreciate the effort and work we put into the HIVE blockchain please consider giving us a Witness vote.

Proud sponsor with @derangedcontests of @brosino , free to play and cash out HIVE rewards, head to Brosino Website now and start playing.

Visit #brits Discord Channel Join #teamuk and make your posts easily found, post with the tag or create a post in teamuk community so your fellow Brits can easily find and support your work. Let's work together to make #hiveuk an active community on the Hive Blockchain.

#teamuk tag is followed and actively upvoted by @teamuksupport

I distribute coffee roasting machines and also espresso coffee machines and roast my own Speciality Coffee Range. being one of the premium coffee suppliers Yorkshire including a wide range of filter coffee sachets. Finally I have a dedicated website to my Artisan small batch roasted coffee featuring roast and post packs and super easy coffee subscriptions.

The Coffee Break Discord Voice Chat Show, in @thealliance Mondays 10pm UTC hosted by @c0ff33a and @enginewitty

created by @derangedvisions

Vote for my Witness

Sort: Β 

Hot coffee and cold storage as it should be my friend

Thanks I’m sweating over 6 batches of 20kg plus each of coffee - that’s a whole load of roasted coffee!

This is quite interesting. Haven't seen any big stake holder do this before!

I’m sure plenty have, just don’t tell you about it. It’s a game of risk really, the more you put keys into things the greater the risk. Keep all your stake in an inactive account and delegate it back to the active account - makes zero difference to how you vote etc but you are a whole lot more secure.

That does make a lot of sense. The number of dapps we're using these days are just too many and it's just the beginning. I'm sure it'll keep rising and securing keys and funds should be a big talking point in the coming days.

Great idea, thanks.

Thanks I’m glad you like it.

Welcome to the party...Fashionably late 😎

I’m always late to the good stuff lol. I’ve been thinking about doing this for a while, the growing value of my wallet finally gave me a wake up call.

Very clever, these Brits...!!! πŸ˜‰ That idea is amazeballs!

Thank you very much, I’m pleased you liked it!

That's a very sensible idea, I've thought about doing it myself TBH but I keep my main password and owner key offline so I don't mind having my keys stored in Keychain, but your route is absolutely the most secure!

Sorry to hear you're dropping down the witness rankings, one of those reasons will be the LEO witness getting set up! You've still got my vote, but it's insignificant.

Now I’ve got a reasonable stake in Hive and I was looking at my account value - it worried me a little how much I use my keys in all sorts of front ends and dapps. If I put most of my investment in a unused account and delegate it back it will feel much safer for me.

Oh I was deliberately pushed down by everyone’s favorite reward pool milker.

It is safer.

Damn, I just tracked back to see who you're talking about, I thought he'd given up, sad to say not quite!

That sounds like an Awesome Idea to Me!
Thanks for the tip!
And...
Have an Awesome Eve.
πŸ‘πŸΌπŸ˜πŸ‘πŸΌ

Thank you very much, I can’t take the credit it was @guiltyparties original concept. It does take the risk out of having a very active account with a large stake in it.

Thank You &
@guiltyparties
The idea is priceless!!!
πŸ‘πŸΌπŸ˜πŸ‘πŸΌ

That makes total perfect sense to me. Rock your HIVE baby! 😁

Thanks very much, it’s always handy to know these little tricks.

Hi @c0ff33a,
it sounds like good idea how put the risk to the minimum level.
I'm thinking about it and if I never put keys from "cold storage" account to the any frontend and only sign with it in the python console, there is 99.999% no way for key compromise... ;)
So, Hive ON !

When I saw the coffee I only craved for some.
Thank you for all you've been doing as a hive witness

You a smart πŸͺ

can you explain the process real slow for me - blinks

While my stake isn't nearly as large as yours, I actually started doing something similar a few weeks back - I created a "wallet" account with the intention of putting all of my Hive-bought-with-powerdowns-from-that-other-blockchain in it, then delegating it to my "main" account. I managed it once, then got distracted and sent the next couple to myself...lol! One of these days, I might do a few Hive powerdowns and move it - I agree that it seems like a nice extra layer of security. 😌

Smart move!