The Joy of flashing the STEEM account-value!!

in serious-security •  2 years ago  (edited)

Never flash your money around said my dad, it attracts thieves and thugs. Keep it in your pocket or keep it safe and out of sight of strangers.


Because of a few million dollars on steem-display and an Internet full of scammers and thieves our company has had to pay a lot for extended security. No problem for us, we can afford it - but not everyone can and in the class society people in ghettos and slums get beaten up over nothing, what can steemians expect when the whole world can see they have something?

We as a company now have Israelian mossad-trained UN-approved military-protection 24/7 + more cameras, electric fences, and all kinds of cool shit we did not need before when we were somewhat anonymous or at least shielded from a public google search, however it has done wonders for the company in regards of credit-worthyness - but it is kind of sad to now have to experience how tough we have to be, simply to manage our stake properly.

We have heard many stories about extortion, we have heard about murders done to crypto-holders who lived in the wrong community and the reward to risk must have been worth it.

Real Power is something you must TAKE - It cannot be given to you!

What good does a trezor wallet with maximum protection do you if you are kidnapped and extorted to give up your keys? What do you do when strangers send picture of your children from the school or kindergarden extorting you, or else you may never see them again?

Yes - Some of you need to be stressed about these REAL ISSUES!

Basic security for your coins does not stop at encrypted papperwallets and hidden encrypted volumes, password managers and 2FA solutions... That is where it starts!

How to hide your STEEM ACCOUNT BALANCE from anyone but yourself?

By public demand of course. If you as a private citizen, entitled to privacy for yourself and your belongings - you must start writing posts here on STEEM why you want some privacy when it comes to information outsiders can find out about you... like your introduction-post with image of your face + your wallet a click away...

The technology for PRIVACY exists and can be implemented - but ALL OF YOU need to start demanding it!

The technology is easily deployed, you can ask any C++ developer with crypto experience about that. So If you want it, start writing posts about it and make sure #privacy #witnesses #developer and @ned or @sneak know what you want.

Our witness: @fyrst-witness will support steem-wallet and transaction-privacy when proposed - Do you vote for it?

Over at you should easily find a button to click on to vote!
Thank you for reading, now it is up to you if you want to act!


This privacy feature has to be implemented sooner than later on Steem.

yes sir..
you are right..
Yes upvotes do change lives, ive gotten a $1000 upvote once from @thejohalfiles and it inspired me to go all out on steem everyday and he changed y life forever and I a forever grateful an I tru to do what he did for me to others below me on the steemarchy and I love finding potential human capital, we have a responsibility to help foster n intelligent discord where the smartest OR most productive people are rewarded for their smartest and most productive of posts..

I cant believe no one saw this as a problem before the site was created!

I agree with this.

You could also just create a completely anon account and fund from bittrex or elsewhere as a temporary solution.

Yes, true - but I hate to do that even as a temporary solution. The ideal solution would be visibility of account values and money transactions only visible to the involved accounts encrypted by the public keys and decrypted by the private keys. And an export to CSV function for whenever the autitors need an update, like we do with banks, cash and everything else when reporting to book keeping.

Absolutely agree, it is better if the steem power and account value will be hidden from the public eye and only the vote value is visible with its reputation. Sometimes, having those huge digit in steem power will somehow gives inconvenience for the account owner and so for the hackers. I hope they can device a solution on this matter.

Why are wallets open to the public to see on here...i find that kind of weird...its like showing your bank balance to the whole world all the time!

Harder for people to be shady, IMO.

I complete agree but how do we implement it?
If the wallet is hidden isn't still quite easy to find out who the whale is?
OR do you want the steem power of likes also a secret and the earnings on every article...

The solution isn't very clear for me. You say the technology exist so please enlighten us!
''Just encrypt it by public keys'' would still make it visible for bots that just involve in every post right?

Blind signatures. Develops know how and choose not to.

really good point ... By tracking the trending Posts , it would still be easy to find out who does make a lot of money , even if the Reward is hidden.

I AGREE, there is no reason to show the account value to those that aren't the encrypted account holder. You can already see ones' prestige by the number next to username, so the account value really isn't desirable for the reasons you've stated.


Set up a company, let the company own the Steem Account rather than an individual. Why not that solution?

Setting up a company will involve additional costs, compliance reporting, etc. If the account is worth a few millions, that may make sense.

Yeah but thats the only option if your account is worth millions.

But all the transactions are visible as well.

after reading your post I cannot other than fully agree!

When I came to steemit 2 months ago for the first time, I found it rather funny and "liberating" that everything is completely visible, but in fact this is obviously crazy!

But isn't this also an inherent problem of the whole underlying blockchain technique?
Everything is stuck forever in that chain which is sort of in the public domain.?

They could set up an account tree where your main account controls your puppet accounts. Those puppet accounts could have hidden wallet value and you could transfer to them in theory using blind transfer or similar.

I'm afraid all this will be next to impossible; the whole fundamentals are what they are and probably it will prove to be impossible to change it or the whole blockchain will have to be dismantled and rebuild anew.

Because, what about:


literally everything is out in the open!

That's a good idea....

Problem is, the whole point is that the anarchist community wants rid of central banks so its going to be like banging your head against a brick wall trying to get them to act more like a bank sadly :-(

  ·  2 years ago (edited)

Really the safest thing is probably to have a main account that you keep funds on and then delegate any steem power you need to your active account/s. You can probably find out who delegated it but it won't be this single point of failure, and won't be so obvious. Right now it's like my Facebook page is also my Pay Pal account.

That seems to be a good point. I guess it's not that hard to do for anyone.

what you are saying is correct but blogging is a way for bloggers to get connected with followers. the relationship between writer and followers is best when followers know about blogger they follow. An anonymous account will not give you this flexibility. Its hard to get followers with completely anonymous identity. Why somebody will follow you if they don't know anything about the author unless you are a god writer.

You the transfer of the funds would still be visible on both accounts. You could just follow the transfers until you find the real holder.

You would need multiple accounts and move over several hops.

Stealth transfers solve that. So would blind signature schemes.

You seem to have a pretty good grasp of the subject. Have you got any posts on the topic of hiding wallets?

I also would like to know more on this topic.

Look into bitcoin mixers etc. With something like bitshares it becomes very easy also to move money between different currencies and then perhaps send the money to some kind of mixer to help launder the account into different other accounts. It is very hard to follow the paper trail once you start trading the crypto into different other cryptocurrencies.

  ·  2 years ago (edited)

I don't think you understand, first bitcoin mixers only work for bitcoin... obviously... but the main problem with Steemit that we're talking about concerns using Steem Power. That steem has to come from somewhere, so how could you cover that up? Unlike Steemit, Bitcoin doesn't have a Steem Power-like function where holding it somewhere serves a function.

Well explained, that sort of centralization could turn out to be one of the major pitfalls of the community if we can't figure something out. Hadn't thought about it a lot personally since i'm a newer member. To the drawing board we go.

If you are gonna properly launder crypto then you are gonna have to use different altcoins. You get mixers for things other than bitcoin, you said: "first bitcoin mixers only work for bitcoin... obviously" that is not true. There has been some writing on mixers using smart contracts with ethereum. I don't see why one couldn't launder steem.

I do not share anything like how much money or crypto coins I have... not that I have much to show right now anyway.. but even if I did I would not make it public like a lot of the people crypto holders do out there... stupid to show your complete hand..

If they can't link it to your real person, it doesn't pose much of an issue. I certainly don't share my steemit name with people I know in real life.

  ·  2 years ago (edited)

That solves the problem only as far as people that are fine with remaining anonymous on Steemit, which is to say it doesn't solve the problem.

ezimedia, your wallet is publicly visible on steemit. That's the glitch in this platform they're talking about.

sorry but can u explain this a bit further?

So basically any person who knows what your username is on steem, can check your wallet balance. Thus if they know you have a great deal of money then can put a gun to your head and demand that you send all your money to an exchange or wallet of their choice. That being said this same is true for bitcoin or ethereum for example. If someone has my ethereum address then they can go have a look how much I have in my wallet at a given time and perhaps with the help of some persuasion and a gun they could get me to transfer them that amount. Does that make sense?

Yeah, I think the main solution is to just not link your real name with your account. Tough for celebrities, but they should probably keep steem power on an alt and shadow vote with it.

Yea that's probably the most secure method and I hope there's development in this area to make it really clear and simple to create these things.

Jesus. That's pretty scary! Lucky I'm not "steemit rich" HA! Wish I had to worry about but so far, I think I'm not a target. But I can see issues that come up that can't be fixed because of the blockchain. Kind of a double edged sword.

hey man thanks a lot for that i was also curious about the anon account @berniesanders was talking about. ye this is a serious issue to correct! thanks again =]

Where can they look at your eth eallet

  ·  2 years ago (edited)

Etherscan or any Ethereum blockexplorer.

The difference is if no one knows your Ethereum address they can't look it up and there's no clear connection as to what exactly the nature of the transactions were for, whereas with Steemit everything is very clearly associated with you and there's far more direct information about the source and destination of those transactions.

i agree

Or just move it completely out of Steem and into Monero, Zcash, or any other anonymous coins.

Verge is 7cent, way less than monero and zcash.

Just because its cheap doesn't mean it's good.....

the only thing the other 2 got is first mover, the technology are the same with all of them.

@fyrstikken, what if the way we keep our wallets safe in the future is by the use of our fingerprint... ie. like the iphone... could that work?

That is even more dumb because it will link your flesh and blood identity to your account. That will not be safe for you.

What the bittrex?

Of course @fyrstikken, but the idea is not to do it as a temporary solution, as the friend says @berniesanders, I agree with him, so the question is in the visibility of those transactions that only have to see those accounts involved "encrypted" by public and private keys , I think it will be the best.

Stop spamming meaningless comments in another meaningful post, just to start, the rest do as @charitybot stated.

Contribute to discussions and be yourself.

Are you ever barking up the wrong tree.

great to see this addressed.

I've definitely debated Powering Down as Steem price increases, for this reason alone.

Should Steem moon at some point, I really don't want it publicly visible what my SP is worth.

That alone should be something to consider, if we're collectively wanting Steem value to rise. Both from the side that it may be a deterrent for large Steem holders to keep Powered Up, and that potential investors may not like the idea of having to keep their investment size publicly exposed.

I've rarely ever gotten involved in the the witness voting, but you've got my support for this issue alone.

Appreciated your service in bringing voice to this matter and initiating the change towards a solution that protects the privacy of Steem investors. 🙏

Exactly my point. Why would any big holder keep holding SP if the price goes to $100? $1000?

At that point it would make more sense to power down and start a company in the real world.

Yeah, a lot of people holding crypto even in Russia got robbed. But how do you think it is possible for someone to know what your account worth? If you haven't ever flashed your face or whatever?

If using a pseudo name and have kept identity secret a whole time, sure.

For others whose profile names match their real names or have revealed them along the way, it’s a different story...

They'll find out eventually after you post enough. Analytic techniques allow for it to be very difficult to not link your flesh identity to your pseudonym.

  ·  2 years ago (edited)

The only good thing when you have it all in STEEM POWER is that the thief must consider he gets only 10% after one week and he must have a damn good plan to make sure the owner will not recover his account.... If i was a kidnapper I would prioritize other coin holders over STEEM ;)

It would however still be worth it for the thief even if he only got 10% and that 10% was for a large amount

Yeah, it's hard enough to get steem out when trying to do it legit haha.

I agree with you, So what next step

even if no one could access it all or not... would you still want your net worth publicly exposed...? 🤔

10% of 10 million dollars is a lot of money.

That is naive. If you have it in Steem Power the thief could coerce you into delegating your SP to them, or upvoting their accounts, and then what? Then you might keep your account indefinitely but lose control over how you spend your SP. Coercion is the issue.

  ·  2 years ago (edited)

So you are describing a scenario where the thief has control over you for a long time...

PS Have you forgotten about account recovery ?

It's not the account which you have to secure. The owner of the account has to be secure as well. Ever heard of extortion?

Scenario, corrupt law enforcement matches an account with a flesh and blood identity. Then one of the agents demand a donation to a cause which makes their lives easier or else...

  ·  2 years ago (edited)

If you're that worried (as in you're that wealthy and in a position that could make you that much of a target) then you could filter the steem power setting it up on multiple accounts that are very difficult to lead directly back to you.

Thank you for posting @fyrstikken.

Appreciate your post speaking out on this issue......freedom and privacy stand or fall together.

bleujay and bentleycapital are in total agreement with you and you have our support.

Wishing you all the best in your endeavour.


I am very glad you are talking about this because I believe your voice is likely to be heard. I know others have talked about this in the past, but I don't see this being taken as seriously as I would like it to be.

This is the only real negative I see on this platform. Any other problems are rather trivial, but like you say, this could get someone hurt.

Thank you for talking about it and I hope this conversation gets some traction.

This is the only real negative I see on this platform. Any other problems are rather trivial, but like you say, this could get someone hurt.

Censorship and the fact that users can't express themselves freely for fear of being downvoted by a whale is also a huge problem imo.

You do have a point there. In certain situations, that comes too close to theft, albeit without the violence.

Your welcome, Indeed lets make sure we get this conversation some traction.
It needs to be seriously addressed.

This is a serious issue that many have not thought about. This needs to be addressed immediatly.

I have thought about this too. It should be an optional. The right to flaunt your wealth on steemit should be optional. Not sure what the purpose is apart from promoting more investments into Steemit.

It encourages e to participate. But yes, the reality of having any sort of monetary value share publicly could be be a security issue depending on where you live.

Yeah, it's not the greatest feature. I think it causes people to follow whales around a bit too much as well.

Yea it's not like they need to make it a private blockchain just make it so you have to dig a bit to see that information.

I agree with you @diggndeeper and let's be fair to SteemIt too here. The theft that took place in person actually shocked quite a few people because many expected that theft would always be digital. I think this can be something SteemIt adds to it, if it chooses (as @fyrstikken may say if we ask enough), but I don't think SteemIt intended to bring harm or considered this would become an issue. The theft shocked quite a few people at the time.

wow! I think I agree with you on that privacy policy and security on people's account cos as for me, that doesn't have any good amount in my steem account. So seeing people's accounts makes me wanna work hard to arrive at such figure but the human mind is so dangerous and for that reason, I totally agree with you. And for such good post am willing to follow and upvote you.

Agreed, Our security is being compromised just to get more sign ups by showing off the wallet balance.

Seriously, Some Action has to be taken immediatly!

the wallet balance IS being showed to get signups, so what? lol people can hold their Steempower in multiple accounts but ten it wont do them s good, wont get s much curation, but yeh we need black steem

OR MAYBE NOT maybe we need money to be public? Maybe attracting thieves is just the opportunity cost, i mean you cant just mke teem accounts private, the whole point is transparency, and you can just hold money in bittrex have some anon steem accounts, but no steempower, SO communities will fix this, and also we will have privacy BUT then it wont be as popular....

so its a trade off

Yep, especially those who has notoriety as personalities. It's one thing to assume someone has money because they're popular on youtube, it's another thing to basically see their bank account balance.

its not a bank account balance its steem blockchain wallet, it is up to the user t simply not reveal who they are! But we will have black steem, picokernal talked about that, and its definitely happening also thejohafiles talked about it last year, hah the richer the steemian the more interested they are in funding private steem accounts,

The answer is on EOS not steem, EOS will facilitate the privacy from the beginning

So what is "black Steem"?

Well they can always remove their steem and have another account delegating all the steem power. On the other hand that just makes it harder to find out and less obvious. I think the nature of the steem blockchain is people will just have to get used to it being public in some degree because otherwise it would need to be a private blockchain like Monero.

Yes I think its a Bonus to get to show off your account balance, it attracts bad people sure, but so does everything! its not a stem issue its a human issue

The public balance ALSO attracts Good people ad investors and fans and loyal followers who will work hard to impress the steem millionaire

The public Balance is a GREAT thing its what i LOVE about steem.... and so what if it attracts thieves and scammers, tell them good luck and protect your keys and they won't be able to do anything.. its blockchain... and it would be a death sentence to fuck with fyrstikken he has an Army of loyal workers on his payroll, he owns his entire block basically, and he has crazy security, if anyone even tried to fuck with him theyd be dead and no one would investigate. It's a really serious social fortress he has and we should all take these precautions, the more news stories I hear about kidnappings and bitcoin and crypto related shenanigans the more I wonder about how to avoid becoming another statistic

The more money we make the scarier it gets, but steempower at least holds a deterant, even if kidnapped someone would have to hold you for 3 months to wait for the steem power down... thats why its good to hold your keys in a big Bank building, one you can actually can't do that shit in the USA or Europe... only few nations on the planet will respect your private property, makes me think a memorized brain key 12 word phrase is th way to go

I really see a huge potential for brain keys stored as mnemonically memorable songs, so that you can never forget your keys.... and we will find a solution for the torture attack vector. i think about that all the time,

The team at @agorise already developed Stealth accounts for Graphene. So I know it can be done.

I felt you were being sarcastic about the introductory post and image - but hey, maybe I misread you. You're right about theft - it can happen digitally and it can happen in person too. I feel it's wonderful if people want to tell the world who they are, but they should be aware that there may be consequences for this, such as what happened to that one guy who had a physical theft of his crypto. You can't tell someone you have none when they can SEE your balance!!!

For new people, consider this when you use #introduceyourself with an image of who you are. Facial recognition is only going to get better.

I felt you were being sarcastic about the introductory post and image - but hey, maybe I misread you.

No sarcasm. These are real issues that we should and can do something about before more people get hurt around the world just because of STEEM. Please read the whole article and see if you want to conclude or dismiss.

I have always thought this was a pretty crazy platform design and you are absolutely right, it could easily be coded out. I wonder what the thought process was behind it that made the dev's think that it was more important than privacy?

I will write a post about it tomorrow.

The idea is to increase the trustless nature of the blockchain, right? If you can't see the account values, it is harder (or impossible) to detect fraudulent activity on the blockchain.

Then there is the question: Who determines what activity is fraudulent? It's not an easy one.

I don't know how I feel about this... Privacy is good to have, although these changes may have far reaching ramifications relating to legal issues and the security of the network. I'll have to think about it.

I am not a pet for the current failing systems often referred to as legal, fraudulent, government etc. I am here to support those who change the world, and by that we change governments and we change everything! Julius Cesar does not rule anymore and Rome is famous for its many ruins.

I have created my post here as promised. Good to see @berniesanders getting on board too. Also I have voted for your witness @fyrstikken. Can't believe I had't seen that before.

More power to you!