You are viewing a single comment's thread from:

RE: Introducing Steem Automated - STEEM Curation Made Easy - Reward Your Favourite Authors

in #steemdev6 years ago

Can you comment on the security implications of authorizing @steemautomated to use one's posting role? What's the worst that could happen and are there steps in place to limit attacks?

Sort:  

Of course, good question.

The worst thing that can happen is that somebody gains access to all the stored access token that are generated by Steemconnect. In that case the attacker would be able to vote for all the authorised accounts.

When that happens all tokens can be revoked via: https://v2.steemconnect.com/dashboard both the users themselves and I can do that.

The database has been properly secured, and I am building something that will alert me via a text when there is suspicious behaviour.

Coin Marketplace

STEEM 0.16
TRX 0.15
JST 0.029
BTC 58127.19
ETH 2452.98
USDT 1.00
SBD 2.36