Difference between revisions of "Hive Key Management"

From Bee Wiki (HIVE)
Jump to: navigation, search
(Links: @alexaivytorres)
(Links)
 
Line 83: Line 83:
 
* '''@pfunk''' : [https://Hive.blog/steemit-guides/@pfunk/a-user-s-guide-to-the-different-steem-keys-or-passwords A User's Guide to the Different Steem Keys or Passwords] ''June 2016''
 
* '''@pfunk''' : [https://Hive.blog/steemit-guides/@pfunk/a-user-s-guide-to-the-different-steem-keys-or-passwords A User's Guide to the Different Steem Keys or Passwords] ''June 2016''
 
* '''@steemitguide''' : [https://Hive.blog/steemit/@steemitguide/a-complete-guide-on-steemit-permission-keys-posting-owner-active-memo-digital-passwords-with-unique-functionality-that-allows Everything you need to know about Hive's Permission Keys; Posting, Owner, Active, Memo! Digital Passwords with Unique Functionality, that allows you to Securely connect your Hive Account with Third-party Services] ''January 2017''
 
* '''@steemitguide''' : [https://Hive.blog/steemit/@steemitguide/a-complete-guide-on-steemit-permission-keys-posting-owner-active-memo-digital-passwords-with-unique-functionality-that-allows Everything you need to know about Hive's Permission Keys; Posting, Owner, Active, Memo! Digital Passwords with Unique Functionality, that allows you to Securely connect your Hive Account with Third-party Services] ''January 2017''
* '''@ramblin-bob''' : [https://Hive.blog/steemit/@ramblin-bob/how-i-nearly-lost-my-steemit-account-and-all-my-steem-a-warning How I nearly lost my Hive account (and all my STEEM) - A WARNING] ''February 2017''
+
* '''@ramblin-bob''' : [https://Hive.blog/steemit/@ramblin-bob/how-i-nearly-lost-my-steemit-account-and-all-my-steem-a-warning How I nearly lost my Hive account (and all my HIVE) - A WARNING] ''February 2017''
 
* '''@smi''' : [https://Hive.blog/vulnerability/@smi/important-vulnerability-in-password-protection-for-accounts IMPORTANT !!! Vulnerability in password protection for accounts] ''February 2017''
 
* '''@smi''' : [https://Hive.blog/vulnerability/@smi/important-vulnerability-in-password-protection-for-accounts IMPORTANT !!! Vulnerability in password protection for accounts] ''February 2017''
 
* '''@sassal''' : [https://Hive.blog/ethereum/@sassal/2eh9w7-how-to-keeping-your-cryptocurrency-safe How To: Keeping Your Cryptocurrency Safe] ''April 2017''
 
* '''@sassal''' : [https://Hive.blog/ethereum/@sassal/2eh9w7-how-to-keeping-your-cryptocurrency-safe How To: Keeping Your Cryptocurrency Safe] ''April 2017''

Latest revision as of 04:13, 18 September 2020

To keep your Hive account secure you must save your master password and keep it somewhere safe. The master password is used to derive all keys for your account, including the owner key. If logging in with your post key, make sure you don't overwrite or misplace your original master password.

The Hive.blog FAQ explains why the password is long and random for maximum account security. There is no way to recover your account if you lose your password or owner key! Because your account has real value, it is very important that you save your master password somewhere safe where you will not lose it.[1]

It is also a strongly recommended that you store an offline copy of your password somewhere safe in case of a hard drive failure or other calamity. Consider digital offline storage, such as an external disk or flash drive, as well as printed paper. Use a safe deposit box for best redundancy. Fabian Schuh (@xeroc)'s post on a Hive Paperwallet Generator is an excellent resource.[2]

In June 7th 2017 Krzysztof Szumny (@noisy) found a flaw in design that made his cousin accidentally pasted his own password into wrong field (a memo field), when he made a transfer. He wrote a script and warned all steemians caught in the same mistake.[3]

Managing Keys

If you don't manage your keys correctly, you are putting your account at risk.

If you get hacked you are giving them access to every key you own on Hive. Loss of your keys will result in loss of access to your account. Keys should be stored privately and safely.

Types of Keys

  • Posting Key
  • Active Key
  • Memo Key
  • Owner Key
  • Master password

Posting Key

The posting key is used exclusively for submitting posts, applying upvotes and downvotes, selecting and deselecting followers, muting accounts and claiming reward balances.

The posting key is the safest way to log into an account. It limits the privilege of the person using it to functions that do not have access to the wallet, thereby maintaining the safety and security of the tokens.

The posting key offers the safest way to access your account on a regular basis and it is recommended that you develop the habit of using it as your primary way of logging into your account.

Active Key

The active key should ONLY need to be used to confirm transaction or trades or change user settings.

Do not use your active key to log in for posting and upvoting on a daily basis. Use your posting key instead.

Memo Key

The Memo Key is used for handling private messages and encrypted transaction memos.

The memo key is the only key that can encrypt and decrypt private messages sent and received via your account.

Owner Key

The owner key is the key with the highest privilege level. It is the key required to change all the other keys. This is the key that should be most carefully safeguarded against loss or theft. With this key your account can be completely taken over by a malicious party. Loss of this key severely limits the operation of the account. The owner key is not directly visible on the Hive.blog website but can be derived from the master password using the CLI Wallet or an API Library like Hive-python.

Master Password

The master password is used to derive all keys above. A hashing function calculates the corresponding private and public keys from the master password, the account name and the key type ("posting", "active", "owner" or "memo"). Having the master password enables to retrieve all private keys of an account. See CLI Wallet's get_private_key_from_password or Hive-python's steembase.account.PasswordKey() on how to derive the keys. Don't use the master password to log into Hive.blog or any other Hive application. Never copy the master password into posts or transaction memos. Use the lower privilege keys to maintain the security of your account.

Please expand upon this subsection.

Locating Hive Keys

Your Hive keys are found in your wallet under the permissions tab. At https://Hive.blog/@yourusername/permissions. Substitute your actual username for yourusername in the example shown.

The page will look something like this image:

Where are your Keys? Click to expand

Securing Your Account

  • Secure your master password generated on your first signing up somewhere no one will find it. You should not need you master password afterwards unless you want to change it.
  • Show your private posting key by clicking the button and copy to a safe place.
  • Show your private active key by clicking the button then copy to a safe place.
  • You can copy the memo private if you need to but you likely won't need it.
  • Now copy your private posting key and use that as your password to login.

Once logging in with the posting key and going back to the permission page it should look like this:

What will it look like when using a Posting Key? Click to Expand


References

  1. How can I keep my account secure, Hive.blog FAQ, retrieved in 17/7/2017
  2. (Paperwallet) Easily secure your account with Hive Paperwallet Generator, Written by Fabian Schuh (@xeroc) in August 2016.
  3. We just hacked 11 accounts on Hive.blog! ~$21 749 in HIVE and HBD is under our control. But we are good guys So..., Written by Krzysztof Szumny (@noisy) in June 7th, 2017

Links

Related articles

External links

In other languages




Help keep this wiki page updated. Register, click in edit, add or modify the text and save.
If you're already a steemian you can be rewarded with steem, see how in @steemcenterwiki.