Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When I recover my account, I can not protect my STEEM #117

Open
ayogom opened this issue Feb 24, 2019 · 4 comments
Open

When I recover my account, I can not protect my STEEM #117

ayogom opened this issue Feb 24, 2019 · 4 comments

Comments

@ayogom
Copy link

ayogom commented Feb 24, 2019

If I use account recovery feature, if I do account recovery,
Only the master key and the owner key are changed. The previous Active key is retained before the recovery.
If the password can be changed immediately after recovery, the problem can be solved,
Passwords can not be changed until 1 hour after recovery.(Because I have already changed it when I recover) This means that my STEEM could be seized through the old Active key that was leaked within this hour.

Therefore, I think that the password of the account can change immediately after the account recovery, or that all keys must be recovered to the active key / posting key at the same time.

@Gandalf-the-Grey
Copy link

When you are in this situation (someone has your current owner key), it's most likely already too late to save your liquid funds.

@ayogom
Copy link
Author

ayogom commented Mar 26, 2019

When you are in this situation (someone has your current owner key), it's most likely already too late to save your liquid funds.

I agree with your opinion, but would not it be nice if you could keep a little bit of your own property?

@steemdevelopment
Copy link

keep your liquid funds in savings. it might take 3 days but it gives you 3 days to act.

@mvandeberg
Copy link

Only the owner authority has a limit of being changed once an hour. There is nothing preventing you from changing your active auth immediately after recovering the account. I think what is happening here is that master passwords change all three auths and process of changing your password requires changing the owner auth. Instead, the Steem wallet should recover the account (changing the owner auth) and in the same transaction change the active and posting auths to match the new master password. These changes would be done entirely client side and require no changes to blockchain code. Moving this to the wallet repo to re-evaluate that entire process to ensure it is as secure as can be.

@mvandeberg mvandeberg transferred this issue from steemit/steem Nov 19, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants