Scammers everywhere - Be careful with your Keys and Passwords

in #steemit7 years ago (edited)

background-3234504_960_720.jpg

Never use your Master Password to login on Steemit please!

Think most are aware about some of the important security rules on this platform but just to repeat it given a friend of mine today got hacked and the account was stolen. We do not know what exactly happened but the account was lost and a certain account has started power down and transferred the available funds to his / her account already. There is not much one can do apart from really being careful on some things.

  • NEVER click on any link in any post, comment or wallet message before you did not investigate it is no phishing attempt Mouseover them to ensure you are aware where they link you to. If you are not sure - do NOT click.
  • NEVER use your Master Password to login on Steemit - as DEFAULT use posting key! ALWAYS - only use Active Key for financial transactions - put your Master Password in a safe place (password manager, paper, engrave in a stone (but keep it somewhere no one has access!), put it in more than one safe places but make sure NOT to tell anyone where this is!
  • KEEP ALL your Keys in a safe place!
  • If you got hacked - use the Stolen Account Recovery tool immediately!
  • Let others know your account has been hacked via the channels your connections are active so the can inform the community!
  • Report scammers on https://steem.chat/channel/steemitabuse

cybercrime.png

BE CAREFUL - Do NOT DRINK OR USE DRUGS WHILE USING STEEMIT

Feel free to spread the news so we minimise people falling into a scam trap - follow @arcange and @guiltyparties for more advice on how to protect your account.

Sort:  

In the past few weeks I have seen a lot of fake websites that look like steemit with the goal of stealing the passwords.

Your friend probably visited one of those websites.

Which one is the account receiving the stolen funds?

Seems she was not clicking any phishing link but who know - the receiving account I reported to steemitabuse and prefer not to mention here - I might do later maybe as he seems to have found another victim.

Omg sir i always use my master password i don't know about keys 😟😢😲. What is it and why is it happening😢😢 please guide me about master keys

Are you serious? You need to check the Steemit FAQs: Re Master Password and Keys read this from the official FAQs please:

Why should I be careful with my master password?

The master password is used to derive all keys for your account, including the owner key. If someone has access to your master password, they can steal your account and all of the tokens in it.

What are my different keys for?

Posting key - The posting key allows accounts to post, comment, edit, vote, resteem, and follow or mute other accounts. Most users should be logging into Steemit every day with the posting key. You are more likely to have your password or key compromised the more you use it so a limited posting key exists to restrict the damage that a compromised account key would cause.

Active key - The active key is meant for more sensitive tasks such as transferring funds, power up/down transactions, converting Steem Dollars, voting for witnesses, updating profile details and avatar, and placing a market order.

Memo key - Currently the memo key is not used.

Owner key - The owner key is only meant for use when necessary. It is the most powerful key because it can change any key of an account, including the owner key. Ideally it is meant to be stored offline, and only used to recover a compromised account.

You can check your keys under wallet/permissions:

Screen Shot 2018-04-27 at 17.16.21.png

sir thank you so much after reading your post i was so curious and worried too so already read these FAQ'S

A password manager like Lastpass can help. It won't fill in passwords if you are on a fake site. The reason you see an icon next to links on Steemit is to indicate they are not on Steemit itself. Links in wallet messages should be treated with suspicion.

BTW It should be 'advice' (noun), not 'advise' (verb) in the last line.

Exactly - also use Lastpass - thanks for the hint on my shitty English :-) - correcting.

Sehr wichtige Info, wird gleich resteemed :-)

Merci hombre - heute was am Start für #DanceWeekend?

Gerne, klar Post ist schon online :-)
https://steemit.com/danceweekend/@mikenero/ibngsu8d

Wird resteemed

Thx :-)

mach ich später - gib mr ein oder 2 Stündchen - die Aktualität hat mich eingeholt :-) aber evtl. magst ja auch bisserl German Metal aus den 1980ern

Thank you for bringing this to awareness again, and especially for highlighting the importance of keeping the Master Key safe and NOT using it as default login password!

Never enough caution!

I know how it feels as my account was hacked about a month ago.

Thanks @ana-maria - yeah i remember your issue recently.

Thanks for the reminder.

Sad that a small few have no conscience or scruples.

Human nature eh.

xox

It's very important to remain vigilant at all times when dealing with any form of crypto login or transaction. Scammers are everywhere at the moment, and sadly people are losing everything due to a lapse in concentration.

I think i know what happened, because my account was stolen some days ago. Your friend opened a link and signed up using his password. If you track the replies he got, one of them must be a phishing link.He must contact steemit and his account will be recovered in some hours.
He must report the user who sent him the link. If he doesnt know, I can check it out for him.
I hope that everything works out soon as possible :)

Not sure - I checked my friend's profile and did not discover anything suspicious - she started to account recovery already and I reported this to steemtiabuse. Thanks for offering help.

Hopefully she can recover her account soon. Have a nice Weekend :)

Can´t warn enough of those things! You have to be vigilant all the time. One of the most dangerous phishing attempts is when one got phished that you follow. You tend to not be on your guard too much if a link is being posted by somebody you know/trust/like.

thank you for the information that is very important for everyone @uwelang you very good

Do not drink while using steemit!

Where will one find creativity then?

Good question, different topic lol

Maybe this is the idea for your next topic, "How To Find Creativity On Steemit!"

Scamers try to get your coins on social platforms like twitter and facebook by posting with fake accounts. but also there a dangerous fishing emails with links in them trying to get your private keys.
Never give out your private key to anyone!

Thank you for the contribution and your part to keep the Community secure.

I would recommend to Split the Master Key in three Parts. Write down part 1+2 on a piece of paper anotherone with the parts 1+3 and a last with the parts 2+3.
Now store the papers in different places. In case of a Fire or theft you are safe. You just need to have 2 of these papers - doesn’t matter which one.

Danke für die Erinnerung! Ich muss das auch viel mehr beherzigen in Zukunft......

Ja, ich bitte darum - nicht dass ich Dich eines Tages deswegen zum Essen einladen MUSS :-). Ist nicht einfach im Alltag, ich weiss!

😂😂 Uwe ja dann pass ich jetzt doppelt auf! Schönen Abend Dir!

Jetzt bin ich traurig wg der Date Absage

Och menno nich traurig sein....dann komm mal zum Munich meet up!!!

Du hast so recht, Uwe und man kann es nicht oft genug sagen!

I just posted on this today after two of my friends have been hacked. One for sure followed a link to a bogus page. All we can do is like you have done here, spread the word. Well done.

... aber ich saufe andauernd wenn ich Steemit verwende! Upvote and resteem.

UI, gut tun wissen
Ich pin es mal als Erinnerung an meine Wand...;-)

Thank you for the heads up @uwelang !

It has increase in these few days.Hearing some people were victim of these scammers as well.

While will be careful at all times. I very much liked the Last Disclaimer ;)

That is aweful! I can't stand a thief!

Danke👍 für diesen aufschlussreichen Artikel😊

Aber immer gerne, danke für den Reply

Absolutely right , We should be careful about our password or keys.. Spammer always find the gap of security. Sometimes they sharing link for spamming... so be careful... Thanks @uwelang for giving us such conscious article

Super Tipp wieder Uwe, benutze auch nur den Posting Key. Der Master Key is versteckt :-)

Hi ......@uwelang
It's great to read your post.
I could learn something new.
I'm with you. Hope you and me stay together.

Thank you

Come up with something new in the future

sir @uwelang Thanks for share your good opinion. maximum new steem user make this mistake.

Every steem user should read this article.

Congratulation, your post has been chosen by @sevenfingers because your content is great and very interesting. your content will be displayed on sevenfingers.io

  • Category : Blog

Keep creating great content
we will be there to support you

Support Us With Upvote This Comment

Contact us on discord
sevenfingers

Right sir, we should be careful. Thank you for sharing the important tips as we can be aware of phishing.

Thanks for the warning, in the beginning, i didn't know much about the keys but in the last time i got used to :)

Just yesterday after my first post ever here on Steemit I had a strange experience related to the topic of this post, which gave me stuff for my second blogpost ... https://steemit.com/deutsch/@mrmastercryptow/about-neppers-scammers-von-neppern-schleppern-bauernfaengern

usually I would flag that spam but as your rep is anyway at 19 already I will just tell you - next time.