Were you afraid of Streemian like I was/am??
I was afraid that Streemian.com was another phising site. I mean, they are a third-party app/website after all and I had just submitted my steemit account information to them, worried that they would steal some of my account value once it had accumulated to considerable levels. I even thought of the worst case scenario where they would collect account information from different people and wait for the right moment to steal their steem, so to speak. When the streemian website seemed to have become non-functional, I almost panicked. I contemplated opening another steemit account because my first one had been compromised. After all, I thought, my account was fairly young and I had not invested too much time on it.
However, after studying a bit more about streemian, my fears were reduced significantly. I learned that Streemian does not have access to its users’ funds because of STEEM’s secure three permissions system. Every STEEM account is underpinned by three permissions. These permissions are the owner, active and the posting. Posting is used to enable the user’s password, their cryptographic key or another user to post using the particular account. The streemian app only makes use of the posting permission. This permission grants streemian the ability to post and vote using the subscriber’s STEEM account. The user also has the permission to detach the streemian account from their STEEM account.
Hold up! There is a catch. New posting permission can only be attached to the STEEM account if the transaction has been enabled using the active key. Streemian requests either the user’s STEEM password or active private key. This part was my biggest concern. This key enables anyone to get access to the key owner’s funds. There are some factors that prevent the funds from leaving the STEEM account.
• First, the streemian app is an open source app. It May be reviewed by clicking the banner at the top.
• Secondly, the streemian app is downloadable. The user can download it fully and run it locally via github releases.
• Thirdly, the user’s private key does not leave the browser at any moment. The app does not facilitate the retrieval of the password and private key from the browser. Indeed, the transaction to change account occurs and is signed within the browser. There is no further communication that happens other than collecting the account data as well as broadcasting the change is needed.
• Fourthly, no storage of passwords or private key happens.
Do these factors douse my fears about the Streemian app? Hmm.,. What do you think? Let me know in the comments section.
Quite informative
I have checked the site, really great project, but that using you private key part still scares me abit, point 3
But i can see it's possible to set up the voting, posting permissions and do for funds later or when need be, but one needs to tincker with it first.
Thanks for shedding more light on this. Those were some of my fears too.
Thanks for the info, will dig deeper and try to understand more about it.
I'm on streemian and I think its a good project
I was so scared I left it at the private key part. Now I guess I look into it again. Thank you.
I'm still learning the ropes as well. Thanks for sharing this.
Congratulations @joel-wandimi! You received a personal award!
Click here to view your Board of Honor
Congratulations @joel-wandimi! You received a personal award!
You can view your badges on your Steem Board and compare to others on the Steem Ranking
Vote for @Steemitboard as a witness to get one more award and increased upvotes!