Author Topic: New "Steemit style" login for Bitshares.org/wallet  (Read 6107 times)

0 Members and 1 Guest are viewing this topic.

Offline fluxer555

  • Hero Member
  • *****
  • Posts: 749
    • View Profile
I'm not sure I understand what you mean. Bitshares is a business. We should decide. And we have- showcasing both options is the decision made thus far. I'm sharing my opinion based on all the problems that it is causing our users.

Offline fav

  • Hero Member
  • *****
  • Posts: 4278
  • No Pain, No Gain
    • View Profile
    • Follow Me!
  • BitShares: fav
Will the BitShares community please learn the lessons that Steemit had to learn the hard way?

Regular users cannot be trusted to generate high-entropy passwords suitable for the Account Model.

I submitted an issue on GitHub regarding this.
+5%
Not only this, but half of the customer support requests involve confusing the account model with the wallet model. We should stick to having only one option and having the other option in an "Advanced" tab or something similar.

that's up for businesses to decide. core wallet should showcase every possible option

Offline fluxer555

  • Hero Member
  • *****
  • Posts: 749
    • View Profile
Will the BitShares community please learn the lessons that Steemit had to learn the hard way?

Regular users cannot be trusted to generate high-entropy passwords suitable for the Account Model.

I submitted an issue on GitHub regarding this.
+5%
Not only this, but half of the customer support requests involve confusing the account model with the wallet model. We should stick to having only one option and having the other option in an "Advanced" tab or something similar.

Offline arhag

  • Hero Member
  • *****
  • Posts: 1214
    • View Profile
    • My posts on Steem
  • BitShares: arhag
  • GitHub: arhag
Will the BitShares community please learn the lessons that Steemit had to learn the hard way?

Regular users cannot be trusted to generate high-entropy passwords suitable for the Account Model.

I submitted an issue on GitHub regarding this.

Offline Thom

Hi guys,
I see that openledger now has the option to login as wallet model and account model.
Can you tell me if it is possible to "convert" an account that was initially created as wallet model to an account model?

Yes, I am quite certain you can begin to use the login anywhere model if you like. Make sure you use a long password without dictionary words or you will be dramatically increasing your chances to be brute force hacked. YOU are responsible for your wallet's security! Act accordingly.
Injustice anywhere is a threat to justice everywhere - MLK |  Verbaltech2 Witness Reports: https://bitsharestalk.org/index.php/topic,23902.0.html

Offline gn1

  • Full Member
  • ***
  • Posts: 129
    • View Profile
Hi guys,
I see that openledger now has the option to login as wallet model and account model.
Can you tell me if it is possible to "convert" an account that was initially created as wallet model to an account model?
I'm a BitShares enthusiast in Japan, spreading BitShares daily to the Japanese people through https://genxnotes.com. Help us grow bitJPY together, so that bitUSD/bitJPY market pair will become the most popular market worldwide! Imagine what kind of world it will become when we execute this.

Offline tbone

  • Hero Member
  • *****
  • Posts: 632
    • View Profile
  • BitShares: tbone2
Excellent! Lots of great features. I am very appreciative of your and svk's work. Thanks

One thing though
As long as you choose a sufficiently long and complex password (use a password manager!), your keys are safe.
...and so long as you also have a 100% clean OS; in an isolated environment, trust the OS image, trust your internet connection isn't routed via an attacker, and don't fuck up by accidentally logging in via a potentially compromised computer.
WOOPS! Time to start over again and secure a new account...

Keyloggers now have the potential to ruin your financial life. New customers are going to be scared away until this is resolved with hardware wallet (trezor) support

Only then you're safe

I would welcome being proven wrong :)

You should use Zemana AntiLogger.  Don't type anything sensitive on a computer that doesn't have AntiLogger installed.  And use a password manager so you can have a different extremely long password for every log in.
So: use antilogger to type in extremely long password, then change the bts password whilst logged in? So there's a new password every time?

Zemena antilogger reviews don't look too good. Allegedly it encrypts the text you type, then decrypts it so that the website can receive it.
Apparently decent/advanced keyloggers can defeat it. What do you think?

I haven't seen any bad reviews of Zemana as an anti-keylogger, and it's been around for years.  But they also do anti-malware now, and I'm not too sure how good that functionality is.  Maybe that's where the review comes from.  Either way, I doubt Zemana or any anti-keylogger is 100%, and certainly wouldn't rely on it alone, but it's an extra layer of protection in conjunction with anti-virus and anti-malware software, and it's pretty lightweight..  As for using Antilogger, it just runs in the background, and it should start up automatically when your computer starts. 

But I was saying previously it's a password manager that enables you to realistically use very long passwords (40+ upper case, lower case, numbers, and special characters), otherwise you couldn't possibly remember them.  The password manager also enables you to use a different very strong password for everything you log into, which is another good precaution that is really only feasible with a password manager.  Just make sure to use a long master passphrase to secure the password manager itself. 

Speaking of which, I have a fingerprint scanner, so that's a good option for logging into your password manager without having to type your passphrase once let alone multiple times throughout the day (i.e. when it times out, which you can also adjust).  The fingerprint scanner is obviously really convenient, and it's also safer since the previously discussed keylogger protection is unlikely 100%.  But if you don't have a fingerprint scanner and want to be extra safe logging into your password manager, you can use the password manager's virtual keyboard login screen.  Hope this helps.

Offline Permie

  • Hero Member
  • *****
  • Posts: 606
  • BitShares is the mycelium of the financial-earth
    • View Profile
  • BitShares: krimduss
just keep your anti vir and malwarebytes updated. no need for some useless bloatware
Whats the dollar limit for your level of trust in antivirus software?
One mistake and it's gone forever, right?

Sorry to bang on about it, but I'm certain well capitalized investors are scared away from trading on the DEX for security reasons.

Would a multi-sig login from 2 separate computers defeat all dragnet-type threats?
I'm not talking about defeating a dedicated attacker targeting a specific individual
JonnyBitcoin votes for liquidity and simplicity. Make him your proxy?
BTSDEX.COM

Offline karnal

  • Hero Member
  • *****
  • Posts: 1068
    • View Profile
Lots of nice changes with this one, good job  +5%

Offline fav

  • Hero Member
  • *****
  • Posts: 4278
  • No Pain, No Gain
    • View Profile
    • Follow Me!
  • BitShares: fav
just keep your anti vir and malwarebytes updated. no need for some useless bloatware

Offline Permie

  • Hero Member
  • *****
  • Posts: 606
  • BitShares is the mycelium of the financial-earth
    • View Profile
  • BitShares: krimduss
Excellent! Lots of great features. I am very appreciative of your and svk's work. Thanks

One thing though
As long as you choose a sufficiently long and complex password (use a password manager!), your keys are safe.
...and so long as you also have a 100% clean OS; in an isolated environment, trust the OS image, trust your internet connection isn't routed via an attacker, and don't fuck up by accidentally logging in via a potentially compromised computer.
WOOPS! Time to start over again and secure a new account...

Keyloggers now have the potential to ruin your financial life. New customers are going to be scared away until this is resolved with hardware wallet (trezor) support

Only then you're safe

I would welcome being proven wrong :)

You should use Zemana AntiLogger.  Don't type anything sensitive on a computer that doesn't have AntiLogger installed.  And use a password manager so you can have a different extremely long password for every log in.
So: use antilogger to type in extremely long password, then change the bts password whilst logged in? So there's a new password every time?

Zemena antilogger reviews don't look too good. Allegedly it encrypts the text you type, then decrypts it so that the website can receive it.
Apparently decent/advanced keyloggers can defeat it. What do you think?
JonnyBitcoin votes for liquidity and simplicity. Make him your proxy?
BTSDEX.COM

Offline tbone

  • Hero Member
  • *****
  • Posts: 632
    • View Profile
  • BitShares: tbone2
Excellent! Lots of great features. I am very appreciative of your and svk's work. Thanks

One thing though
As long as you choose a sufficiently long and complex password (use a password manager!), your keys are safe.
...and so long as you also have a 100% clean OS; in an isolated environment, trust the OS image, trust your internet connection isn't routed via an attacker, and don't fuck up by accidentally logging in via a potentially compromised computer.
WOOPS! Time to start over again and secure a new account...

Keyloggers now have the potential to ruin your financial life. New customers are going to be scared away until this is resolved with hardware wallet (trezor) support

Only then you're safe

I would welcome being proven wrong :)

You should use Zemana AntiLogger.  Don't type anything sensitive on a computer that doesn't have AntiLogger installed.  And use a password manager so you can have a different extremely long password for every log in. 

Offline yvv

  • Hero Member
  • *****
  • Posts: 1186
    • View Profile
Quote
Move the 'borrow X' buttons to the Buy/Sell boxes

Shit! I thought it is gone!!!

To be serious, GUI improved a lot during last couple of month. Good job.

Offline Thom

WOW! @svk you really hit it out of the park with these changes.  A W E S O M E !
Injustice anywhere is a threat to justice everywhere - MLK |  Verbaltech2 Witness Reports: https://bitsharestalk.org/index.php/topic,23902.0.html

Offline Permie

  • Hero Member
  • *****
  • Posts: 606
  • BitShares is the mycelium of the financial-earth
    • View Profile
  • BitShares: krimduss
Excellent! Lots of great features. I am very appreciative of your and svk's work. Thanks

One thing though
As long as you choose a sufficiently long and complex password (use a password manager!), your keys are safe.
...and so long as you also have a 100% clean OS; in an isolated environment, trust the OS image, trust your internet connection isn't routed via an attacker, and don't fuck up by accidentally logging in via a potentially compromised computer.
WOOPS! Time to start over again and secure a new account...

Keyloggers now have the potential to ruin your financial life. New customers are going to be scared away until this is resolved with hardware wallet (trezor) support

Only then you're safe

I would welcome being proven wrong :)
JonnyBitcoin votes for liquidity and simplicity. Make him your proxy?
BTSDEX.COM