My Suggestion To Implement Two Factor Authentication On Steemit
Words
348
Reading
2 min
Listen
Play
9y
Components
It has almost been a month since the Steemit Hack and I still do not see any option to add 2FA to my account. I was sure I read the message correctly from the security team when it said they would be adding 2FA to the site, but I have still not seen anything yet. Enabling 2FA is a basic necessary first step towards increased security.
Proposal
What is 2FA?
Two Factor Authentication is when a separate device (i.e. Google Authenticator or Authy app on your iPhone or Android device) generates random passwords in a regular time interval for you to use when logging in. So if someone hacks your social network password they would also need to get your 2FA password too which is usually over the scope of the hack.
We have already seen regular passwords breached here at STEEMIT last month. Hackers these days are more sophisticated and determined to hack as much as they can as fast as they can. For example look at what just happened at Bitfinex, a hacker drew down 60 million in funds in the blink of an eye, and with so much of peoples hard earned STEEM, users deserve the option to POWER UP our security.
STEEMIT Needs to get Funds in Cold Storage If they are not already!
What we have learned from the Bitfinex Hack is that in order to protect the funds they must be in cold storage, offline, not connected to the internet. Especially since our funds are locked up for 2 years while POWERED UP at STEEMIT, this should be a given.
STEEMIT Needs to Shift some of the Crazy Money to Security NOW!
Mockups / Examples
When we apply 2FA we receive a nitification from steemit that somebody is trying to log in to your account. In this way our accounts are more saved from hackers.
Benefits
- 2FA makes our accounts more secure because a hacker needs to possess first your device before he can login.
Posted on Utopian.io - Rewarding Open Source Contributors