Huh, I didn't realize that Peakd.com can be the blogging platform. That makes sense, since once I went on Peakd, I saw my "blog" posts. (I mean, really, is this a "weblog" or a bulletin board / web forum? But I digress.) Hivesigner github documentation says your private key doesn't leave your machine, and it's open source, so I'm inclined to believe:
When user login to hivesigner, his private key is available within the interface to sign transaction or sign a message then discarded if the user close the website, desktop app or chrome extension. We never get access to users private keys. The access_token on hivesigner are just Hive signed messages encoded in base64u.
https://github.com/ledgerconnect/hivesigner/wiki/How-Hivesigner-Works%3F
https://github.com/ledgerconnect/hivesigner/wiki/OAuth-2 .
Neither Hive.blog, 3Speak.online, nor Peakd.com is open source, as far as I know. I have no reason to assume any one of these Dapps is more trust-worthy than the next. But Peakd.com doesn't ask for any keys directly, and that alone gives me more confidence in it. You're right it stands to reason that Hive.blog is keeping that posting key on some server.
Personally, I don't like the idea of needing to give any of these Dapps continual posting permission. As an option, I'd be fine with it, provided I also had the option to give permission on a post-by-post basis.
Example A: I go to hivedapp.whatever, I create an account, they ask if I want to give posting permission, I say yes, I give hivedapp.whatever posting permission via hivesigner and my active key, I draft a post, I click "Post," draft immediately gets posted, I draft another, I click "Post," second draft gets immediately posted.
Example B: I go to hivedapp.whatever, I create an account, they ask if I want to give posting permission, I say no, I draft a post, I click "Post," it sends me to hivesigner, I give it my posting key, draft gets posted, I draft another, I click "Post," it again sends me to hivesigner, I again give my posting key, second draft gets posted. (Unless, I'm posting the second draft while hivesigner is still open, per the quote above, then I shouldn't need to enter it again.)
Example B is obviously more work for the user. But if someday hivedapp.whatever gets hacked, no one realizes yet, and a bad actor wants to post under my user misinformation to sway a foreign election (crazy outlandish scenario, I know): Am I wrong that in Example A, it can, and in Example B, it cannot? Also, am I wrong that in example B I would only need to give Hivesigner my posting key?
Thanks.
RE: X-Post from ThreeSpeak community - no, you do not need to give 3speak your Active Key (directly)