scrobble.life
#steem

Steem Basics: Understanding Private Keys

Steem Basics Private Keys v4.jpg

In a previous post we discussed how we are in the process of splitting Condenser (the open source software that powers steemit.com) into two separate applications that will work together seamlessly. One application will handle all the financial functions (wallet) that require a higher level of security, and the other application will handle all the social functions that require a relatively lower level of security. The end result will be two applications that are more secure and optimized for their specific functions.

Private Key Management

This “separation of concerns” is similar in concept to the different types of keys every Steem account holder is given when they create an account. These keys “unlock” different levels of control over an account. One of the advantages of the split will be that it will enable us to create a more intuitive user experience with respect to the use of your keys. For that reason we thought we would take this opportunity to educate any users who are still confused by the private key system on what these keys do and how they can be used safely.

Posting Key

In today’s post we want to focus primarily on the Posting Key and Master Password as these help explain the overall design of Steem’s private key system. Steem’s private keys are “hierarchical” which means that each one enables the key holder to perform a wider variety of activities with the associated account. The “Posting Key” is at the bottom of the hierarchy because it can do the least. It can only be used to perform social activities like posting, commenting, upvoting and downvoting. While these activities are common, they do not require a high level of security, because they do not authorize any operations which can negatively impact token balances.

If you prefer watching to reading, check out this video in which Steemit’s Content Director (@andrarchy) explains Steem’s Private Key system:

Screen Shot 2019-02-20 at 1.55.11 PM.png

To retrieve your Posting Key, go to the permissions tab inside your Steemit wallet. Your public Posting Key will be at the top of the page and alongside it you will see a button that says “SHOW PRIVATE KEY.” When you click on that button you will be prompted to input your Active Key or Master Password. Once you do so, your private Posting Key will be displayed. At this point you might want to consider saving this key to a password manager like LastPass or Dashlane for safe storage.

Permissions v2.png

A user’s keys are vulnerable any time they are entered into an application. A malicious actor could create a fake interface at a domain that is a common misspelling of steemit.com and that requests you input your private keys (phishing). A malicious browser plugin can also gain access to keys stored in your computer’s memory or your web browser’s cookies. Having a Posting Key ensures that the key that is used the most–and is therefore most likely to be acquired by a malicious actor–conveys the least authority. Even if a hacker does get this key, the only things they can do with the account are the social activities (as opposed to financial).

Key Hierarchy v2.jpg

Because the Posting Key has the fewest authorities, there is no harm in always attempting to use the Posting Key if you are not confident about which key should be used. In other words, if all of this sounds confusing, all you need to remember is that the safest option is to only use your Posting Key. If a key with higher authority is required to perform the action, you will be informed by the interface that the Posting Key is insufficient and that another key is required.

In the vast majority of such cases, you will then use your Active Key. But remember to be more cautious in those circumstances. That being said, the Posting Key can certainly be abused too, so users should always be vigilant. We will continue to release posts like this to educate users about how they can protect themselves within the Steem ecosystem.

Master Password

While a hacker acquiring a Posting Key might be unpleasant for the account holder, as long as the rightful account owner still has their Master Password (or their Owner Key), they can always change all the other keys and regain total control over their account.

Password v. Key

One might wonder why the Master Password isn’t also called a “key.” That’s because all of the keys are actually derived from this single password. That’s why it’s called the “Master” password. It is also called the “seed” because it is the first password that is created, and it is from that the rest of the keys spring forth. That’s why it can be used to perform any function on Steem, from social activities to financial activities. Its convenience has led many to use this password for everything, but this is the precise opposite of its intended use.

Since keys can be used to do any activity in Steem apps like steemit.com, the Master Password should be securely stored in a password manager (like LastPass or Dashlane), or offline entirely, and only used for highly-trusted applications, minimizing the risk it could be acquired by a malicious actor. Remember, if you use your private keys right, you be unlikely to use the Master Password ever, therefore sacrificing some convenience for the benefit of security is a worthwhile tradeoff.

Steem Connect and Keychain

Users should always be careful when signing into any site that requests any of their private keys. We at Steemit, Inc. can only speak to the security of steemit.com. Otherwise, we recommend only signing into websites through SteemConnect which is an open-source, universal, login layer for Steem Apps, built by a community developer (@fabien) in collaboration with Steemit, Inc. Think of it as “Facebook Connect” for Steem apps.

Users who do not want to input their private keys into Steem-powered websites can use the the Keychain extension created by the @steemmonsters team. Keychain stores Steem keys in a browser extension which can automatically provide the appropriate keys when prompted by a Steem app, thereby foregoing the need for users to expose their keys by copy-and-pasting them into a website.

steemconnect keychain.jpg

Summary

The goal of this post was to focus primarily on the Posting Key and Master Password because understanding these two items delivers the most insight into the overall design of the system. The Posting Key is at the very bottom of the hierarchy because it grants the least authority, but it is also the key Steemians should be using the most since it governs social functions. The Master Password, on the other hand, is at the very top of the hierarchy because it grants the most authority and is almost never necessary.

We will cover the rest of the keys in future posts, so if you found this informative, be sure to follow @steemitblog and please share this post with anyone who is trying to gain a better understanding of the private key system.

The Steemit Team

Comments · 50

  • @sambr(25)· 2436d

    Thanks, I could enter again

  • @yoshizuki(25)· 2472d

    Very nice tutorial! So glad to see this coming from the Steemit blog, simple to understand information like this is exactly what new users need.

  • @massalariel(25)· 2573d

    I understand the key process and its' need but what I don't understand is when I log into my account and navigate to "key/permissions" and try to copy any key so I can save it outside my account , I cannot. I click "reveal" and it takes me to the log in page. I log in and that sends me back to permissions where I hit reveal again and I am sent back to login. How do i reveal my keys??????? Help!

  • @semtroneum(54)· 2584d

    I cant sell my steem... everytime i try to transfer to blocktrades it says "transaction broadcast error missing active authority..." it's driving me crazy! Help me i want the money back

  • @hikariws(25)· 2632d

    So, I should avoid logging on a Steem app I don't trust, even using my posting key?

    I notice that when I login Dtube or Steem Monsters, I'm inside their domain, so I'm actually sending my password to their web server.

    Some Steem App then can verify my password on blockchain, and save it? And use it on other Steem Apps? Or be hacked and have my password stolen and used?

    Sorry, if my password is sent directly to a Steem App's web server and it's the one validating it on Steem blockchain, I don't feel secure about it. Shouldn't it be using some kind of token or single sign on? In example, many sites allow us to use a standard SSO to log on them, but in this case they redirect us to a SSO authoritative's website (Google in example) and it's in that one we login, then we're redirected back to original site who just recognize the authentication without ever seeing our password.

  • @ayogom(69)· 2648d

    I think the picture of wallet should be changed as below.

  • @zahid0406(36)· 2677d

    Much more informative writings.

  • @zolorakh(45)· 2678d

    I don't get it yet :( I click on the reveal button but the passwords stay the same (***************) like that. I click reveal, I log in, but any of the keys reveal help me out please?

  • @death3002(49)· 2678d

    when i try to view my private posting key it wont let me, i click reveal, log in, and then im logged in but it is still hidden, how do i fix this?

  • @coloradoo(25)· 2687d

    Very nice tutorial & very helpful and concise.

  • @borishaifa(63)· 2700d

    Again and again I try to withdraw SBD to Bittrex from my wallet and get - "Transaction broadcast error" I did it before hundreds of times. I have read all instructions and manuals here, I enter my Active Key I enter memo and... Again the same... "Transaction broadcast error" What is going on? Could anyone help me?

    PS. OK, guys I have helped myself. I have read the instructions one more time and it helped))))) So, for transactions Withdrawal SBD for example - you need NOT all those keys, that are mentioned in your account. But that one, that is saved (if you had done transactions before, at Google Password manager. IMPORTANT. This password start not from "S", or "5" but from "P" only.

  • @oresteg(54)· 2702d

    Mi pregunta con cual clave ingreso a mi monedero para gestionar?

  • @internutter(76)· 2703d

    I'm having immense trouble with this - I can't get into my wallet to obtain the private key because it requires a private key to get in.

    Is there a way to reset this with Steem or is there another way to get this securely?

  • @ftoz(55)· 2703d

    For me absolute stupid way here. Plaese dont name it private key if it is server key. Real private keys should be generate offline and never put into any open file on internet.

  • @ferrys(25)· 2716d

    STEEM, is a token that can be transferred and traded like Bitcoin. STEEM can be converted to STEEM POWER.... Steem is the best. I think, Steem is A Proof of Concept (POC) and are a small exercise to test the design idea or assumption.

  • @ferrys(25)· 2716d

    Thanks.. This post is very good

  • @kshitija360(27)· 2721d

    And when i have to use master key?

  • @kshitija360(27)· 2721d

    Im confised. I have 1 password and after some days i got one transaction id ..what is that then?

  • @dragos75(25)· 2726d

    Hi. I visited for the first time.

  • @allude(25)· 2729d

    Great tutorial. Quite informative even though short. Would like to know, which category does the password generated using the link sent to our emails during sign-up, fall in?

  • @blockchainstudio(72)· 2740d

    Great! Steemit needs more official tutorials. This may also be of interest: Steemconnect login with posting key instead of active key

  • @apshamilton(73)· 2740d

    Great post. What is the memo key for and where does it fit in the security hierarchy?

    Posted using Partiko iOS

  • @doktormuslem(63)· 2742d

    Allow me to translate this post into Indonesian :)

  • @shortshots(65)· 2744d

    Bookmark

    Posted using Partiko iOS

  • @foxkoit(76)· 2744d

    This video was very good ... and it helps lot :)

  • @steevc(80)· 2744d

    I'd hope everyone uses a password manager if some sort as you need unique passwords for each site anyway. Something like Lastpass also reduces risk as it will only supply the password for the real site and not for a fake one.

  • @happyme(72)· 2744d

    It's high time that an official statement was made about the use of keys. Steemit has to be the only site I know of that has left its use and functions to be explained by 3rd parties. These important details need to be front and center for all users, all the time!

    I'm glad to see progress finally being made in this regard.

    Since steem.centerwiki has already done an excellent job of making sense of Steem, it would be prudent and most efficient to simply link to it as a great reference manual.

  • @chrisrice(68)· 2744d

    You separated the Owner Password from the Master Password in your diagram, but aren't they the same thing?

  • @lichtblick(77)· 2744d

    Interesting. Shared with my followers :-)

  • @freedomno1(57)· 2744d

    Definitely one of the most useful posts on sorting steemit out I have seen in a long time excellent post.

  • @ayogom(69)· 2744d

    Good post. I will translate this and share it with our local communication members.

  • @firepower(80)· 2744d

    Excellent work with this! :)

  • @wasim1(65)· 2745d

    Nowadays you people are very active. it is very good ♥

  • @oldtimer(76)· 2745d

    I never got this one: Master Password (or their Owner Key). Are these two different names for the same thing or I'm missing something?

  • @mistakili(77)· 2745d

    esteem app asks for master password. What can you say about that?

  • @brianturner(68)· 2745d

    Definitely very helpful and concise!

  • @llfarms(68)· 2745d

    Very nice tutorial! So glad to see this coming from the Steemit blog, simple to understand information like this is exactly what new users need. I agree with Crim, we need this in one easy to find location with some other FAQ. Nice progress!

  • @paulag(74)· 2745d

    nice tutorial :-)

  • @dipfox(51)· 2745d

    감사합니다

  • @maxdevalue(69)· 2745d

    Thanks for commenting, things are getting better in #Steemit and at #Steem network especially in the area of communication, information, advertising, and projecting Steem to the far ends of the planet earth!

    Thanks @steemitblog for the reminder cum information.

  • @soyrosa(75)· 2745d

    Great video! This really breaks it down so it's useful to newbies but many users that have been here for a long time might have an 'aha' moment too :-)

  • @fredrikaa(74)· 2745d

    Superb video. Having things like this to send new users to when they ask about the keys, or even linking to from the FAQ in different dApps will be really helpful!

    Shame I can't flag people who comment on YouTube though.

  • @yasu24(70)· 2745d

    I resteemed this article. Thank you for the information.

    Posted using Partiko iOS

  • @pablob(45)· 2745d

    yes!

  • @crimsonclad(74)· 2745d

    This is really well put together! Well done~ I'm going to carry it through into some of the new user communities. I hope to see this rolled into the FAQ here or into however you refresh the introductory new user experience for front ends with the upcoming split~

  • @lujosag(43)· 2745d

    Muy buena la inducciòn acerca del manejo de las claves de seguridad de steemit. Gracias.

  • @shortsegments(78)· 2745d

    Thank you, This was a good review of an important topic. I will resteem this post.

  • @harferri(71)· 2745d

    Thank you @steemitblog This information is very useful especially for new users on our pride platform...