The Security in Steem DApps
Social Network with Rewards based on Steem. Are we a target?
Steemit (and the Steem environment) has a quite remarkable quality before other social networks: The possibility of obtaining income by posting. In a very different possibility where you can earn income creating content, there is something much more important to take into account and it is that we are talking about money.
Lately, I learned by force that money should be adequately protected, since money is about the reward for our effort, and no one wants effort thrown away.
In the same way, in Steem, we are many people who dedicate hours and hours to daily activity, where we are rewarded in the form of cryptocurrency, reputation and trajectory our efforts. Now, can you imagine all that vanished in a moment?
The Steem Keys: The total access
Once registered in Steem, we are indicated and warned of a single access key that is necessary for ALL in the Steem blockchain (master key). Post, transfers and memo are the other 3 keys that are visible by having the master key, and having the master key, you can reset the previous ones.
Basically, if someone has access to one of these keys, they can access certain qualities depending on what key they have in their possession.
Source
- Post: Authorize to post, comment, upvote, and follow.
- Memo: Authorize to send private messages and see the private message of who's send you.
- Active: Authorize to transfer, trade in internal market, move and control funds, vote for witnesses.
- Owner: The most important. Authorize to change all other keys, full control of your account.
What happens with the DApps?
We know that Steem's blockchain allows the creation and adaptation of new ways to publish content and take form as Steemit does. From this, several platforms have been born within Steem that make up everything that is nowadays.
The most recognized DApps of Steem and with the longest trajectory are quite supported and with delegations of Steem Power (SP) for the voting of publications in those platforms. To access these platforms, we must enter with our respective keys (as well as in Steemit) to be able to give access to the different options that other apps can offer.
What is the problem?
It begins when there is a possibility that they may be taking something that is yours (yes, I speak of the keys), something that you can stop suspecting those with more trajectory (DTube, Steepshot, Busy..) but still, your time and money, are at stake.
That is why it is difficult to give your access keys once a new DApp appears, and even more so when it is necessary to give some more compromising key such as the active key (funds in possible danger), then there comes the benefit of doubt.
Indeed you have to be quite cautious and know where we are getting, that is why personally, I find it quite disturbing to give my keys when it is not about the post key (although you have to be careful with all).
Source
It adds more reliability and confidence that the application asks for data through Steemconnect, but still, in any case, the application not yet saving key data could make movements, or maybe it is being very paranoid.
I would like to know if you consider it safe to place your keys in DApps. Example: Partiko App