You are viewing a single comment's thread from:

RE: It Seems Like Steemit Accounts Are Getting Hacked RIGHT NOW!!! Yikes

in #steemit8 years ago

My guess is a weak password was involved. People are horrible at creating passwords. We should never be trusted with the task. There are tools like keepass that while they are better than nothing, do not represent an ideal solution, because you don't easily have access to you password on seperate devices.

Here is truth. Passwords just suck. We should not be using passwords for deriving a key. This is the brain wallet problem we've been facing since 2010 when the first brain wallet schemes were launched.

You need multifactor authentication of which part may be a password.
When you think multifactor auth you think SMS and this is wrong minded.
I have a solution that I believe will work and it's blockchain friendly and portable. It's also a bit too long for comment. So I'll make a new posting about it here shortly.

Sort:  

I agree on the password stuff. It is tough to deal with. Also having these as web wallets right now has to provide holes for these hackers to get through. Let me know when you get your post up about the non SMS multi-factor solution you have. I would love to read about it!