You are viewing a single comment's thread from:

RE: Beware Inactive Witnesses - Witness Stats Released

in #witness-category7 years ago

Vote for new witnesses via the website
On top of being able to unvote witnesses you already vote, there is a section to allow you to vote for a new witness. That looks like:
Screen Shot 2017-07-24 at 8.53.12 PM.png

This is redundant functionality to https://steemit.com/~witnesses and soliciting/encouraging people to enter their Steem account active key on any other website is not a good idea.

It erodes the notion that it should be treated very securely, and only on services that have something massive to lose if they breach user trust. Steemit Inc has a vested interest in not breaching user account security, therefore they are far less likely to misuse/store auth keys.

Sort:  

This doesn't really make sense to me nor do I agree.

I'm a programmer with a background in security. I'm not some kid playing around with a keyboard here.

You are essentially saying SteemIt == Steem but that is very wrong. eSteem is an app where you can make transfers. This requires active key. Did you go tell them how bad an idea of their app (that I'm currently using) is?

STEEM connect allows people to delegate via a web interface using their active private key. Should we just tell people to use the cli_wallet because it is safer? What is safer?

The witness voting experience on SteemIt looks like something I made in 5 minutes while on vacation.

Thanks for your input but I also know that I am vested in STEEM and have been building a reputation here based on my real life identity. Basically saying that I'm not to be trusted is ridiculous bro. All of my code is open source once I deem it to be generalized enough to be released.

Also if SteemIt really cared that much about security and preventing users from putting their key on another site, they would have made a OpenAuth plugin to use the SteemIt website as login.

PS: you have 8 witnesses that didn't update to 0.19.0 and 2 of those are actually disabled. You could see that on my website and then go to https://steemit.com/~witnesses

I'm not saying you're not trustworthy, it's that there are degrees of trust. I'm not saying Steemit is Steem, but as far as how deep they are invested in maintaining trust of Steem users, they are the deepest.

I agree the witness voting page isn't great. If you want to fix it up, you could submit a pull request to the Condenser repo.

Witnesses updating to 0.19.1 is not mandatory. One of the two witnesses you mention voluntarily disabled their witness account temporarily only an hour ago, and the other one I am still consciously voting for to leave the door open for them to come back and run a node again. Any other critiques? :P

Lol I just figured it would be nice to inform you in case you didn't know. But you are an active witness, not the problem with the network like some of these other guys.

I will definitely look into submitting a PR on the repo for improving the witness page. I have very little knowledge in react, however.

I appreciate you bringing your concerns to light though. Staying involved and communicating with others is necessary for a network like this to thrive.

See the disclaimer I added to the bottom of the post.

What could be a reason for keeping the old 0.19.0?

There's no real reason to keep the old except not wanting to take the time to upgrade to 0.19.1