Bitcoin Forum

Other => Meta => Topic started by: b-trading on June 25, 2015, 08:10:38 PM



Title: 2FA for more security in bitcointalk forum
Post by: b-trading on June 25, 2015, 08:10:38 PM
Imagine...if i have actived on this forum lets say for about five years...i begin it with newbie rank and for so long until i have legendary rank...and suddenly someone hack and stole my account...and everything is gone...especially my hard worked for about five years in this forum to increase the rank from newbie to legendary...my point is how secure our account here with out 2FA...and if i had an idea to say to theymos to enable 2FA in this forum for more security reason..do you all will be agree with my idea?


Title: Re: 2FA for more security in bitcointalk forum
Post by: hilariousandco on June 25, 2015, 08:21:53 PM
It's coming with the new forum:

https://bitcointalk.org/index.php?topic=523070.0

In addition to normal password authentication, the forum should support various kinds of of alternative authentication. At least password auth, email verification, secret questions, OpenID, PGP, OpenVPN (automatic creation of subnets + IP source verification), and Bitcoin address signing should be supported, with multiple allowable credentials for each auth type. Users should have the option of requiring any combination of these auth types. Like "pgp OR (password AND OpenID)". And users should be able to require that changes to some or all auth types as well as the required combination of types not take effect for some configurable number of days. This allows for different types of recovery methods.

Also, it should be possible to limit the access for each auth type. So one type might be able to only read, but not post, etc. If the Web interface uses the same API that is exposed publicly, then these permissions can be in the form of allowed API commands.


Title: Re: 2FA for more security in bitcointalk forum
Post by: Brewins on June 26, 2015, 01:05:54 AM
Stunna offered a bounty for whoever make 2FA avaliable in the forum, not sure if it still is up.

And if IP source verification is added I see lots of people complaining that they can't access their account because they changed their IP or tried to access the forum from some other place.


And if some people struggle to understand even how activity is calculated, I see how hard will be for them understand and configure all the auths options



Title: Re: 2FA for more security in bitcointalk forum
Post by: Xian01 on June 26, 2015, 01:08:43 AM
I'm sure the 2FA feature will be included in the new forums software that Theymos has spent ~$1.2M USD on, so far...


Title: Re: 2FA for more security in bitcointalk forum
Post by: LouisVuitton on June 26, 2015, 01:39:28 PM
This will be an awesome option! Can't wait.


Title: Re: 2FA for more security in bitcointalk forum
Post by: mmmaybe on June 28, 2015, 01:48:14 AM
Good idea! :)

At first I thought it would be expensive, but as more and more sites have it implemented, it can't be that bad.


Title: Re: 2FA for more security in bitcointalk forum
Post by: photon_coin on June 28, 2015, 01:58:59 AM
not a good idea


Title: Re: 2FA for more security in bitcointalk forum
Post by: Brewins on June 28, 2015, 03:14:15 AM
not a good idea

why not?

Of course not impose it to everyone, but add such option.

I don't think it would be too much compared to the 1M+ already spent in the new forum software


Title: Re: 2FA for more security in bitcointalk forum
Post by: Xialla on June 28, 2015, 01:58:15 PM
At first I thought it would be expensive..

uhh nope, you can have it literally for free with implemented Google 2FA (Authentificator) or with possibility to add yubikey..2FA is must have for any kind of serious web service these days..

not a good idea

why? I really don't see any catch..


Title: Re: 2FA for more security in bitcointalk forum
Post by: baldpope on June 29, 2015, 03:59:12 AM
yea, adding Google 2FA (rather one-time-password) option really makes sense.  Google makes it relatively easy to implement depending on your back-end.

anyway - consider this my +1 for 2fa


Title: Re: 2FA for more security in bitcointalk forum
Post by: koshgel on June 29, 2015, 04:24:44 AM
New forum etc etc..


Title: Re: 2FA for more security in bitcointalk forum
Post by: Quickseller on June 29, 2015, 04:42:20 AM
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware

All that you need in order to prevent damage from being done in the event that your account is hacked:
  • Establish a PGP key that is associated with your account, and sign all addresses that you receive payment to with that address
  • Quickly and publicly report your account as being hacked when you are unable to access it.


Title: Re: 2FA for more security in bitcointalk forum
Post by: hilariousandco on June 29, 2015, 07:54:29 AM
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware


A unique and complex password doesn't matter when you get a keylogger or your account taken other remotely which is what usually happens when people get their account hacked and it's easier said than done to 'Keep your computer clean from malware'. If people did then there wouldn't be an issue.


Title: Re: 2FA for more security in bitcointalk forum
Post by: RappelzReborn on June 29, 2015, 08:09:48 AM
This is already planned for the new forum software , but it will be optional or obligatory ? I mean you can Unlink your account later ? then I guess selling/buying accounts will be dead since you have to give your Gmail (all google services) accounts . but most likely taking some few years since we was expecting a Beta in last December and Release on last Feb. and and it's been months and soon it will become one year .
I don't get it .. why Theymos simply don't tell us how much left so we stop asking questions and rest in peace  :-[


Title: Re: 2FA for more security in bitcointalk forum
Post by: hilariousandco on June 29, 2015, 08:25:39 AM
This is already planned for the new forum software , but it will be optional or obligatory ? I mean you can Unlink your account later ? then I guess selling/buying accounts will be dead since you have to give your Gmail (all google services) accounts . but most likely taking some few years since we was expecting a Beta in last December and Release on last Feb. and and it's been months and soon it will become one year .
I don't get it .. why Theymos simply don't tell us how much left so we stop asking questions and rest in peace  :-[

I'm not sure if it will be obligatory or not, but if you don't use it and your account gets hacked then it should be tough luck. Theymos likely isn't going to give a date because it's hard to give one on a work in progress and if he states a deadline people will only complain when it's missed. The forum needs to be 100% working and secure and it'll take a while to iron out kinks and bugs and unexpected problems can arise so that's why it's silly giving out deadlines unless you are 100% sure.


Title: Re: 2FA for more security in bitcointalk forum
Post by: Quickseller on June 29, 2015, 12:13:17 PM
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware


A unique and complex password doesn't matter when you get a keylogger or your account taken other remotely which is what usually happens when people get their account hacked and it's easier said than done to 'Keep your computer clean from malware'. If people did then there wouldn't be an issue.
Well doing things like avoiding downloading things like QT clients of most altcoins and other random files from untrustworthy entities and to avoid going to sites that are sketchy. Using an antivirus software would probably also help. All of these practices are things that I am going to guess that many people who get malware do not follow.


Title: Re: 2FA for more security in bitcointalk forum
Post by: tiggytomb on June 29, 2015, 12:24:18 PM
I like this idea, I use 2FA on many sites, very easy, quick and an extra layer of security.


Title: Re: 2FA for more security in bitcointalk forum
Post by: el kaka22 on June 29, 2015, 01:27:21 PM
I like this idea, I use 2FA on many sites, very easy, quick and an extra layer of security.
I used to refuse any site that requires me to make a 2FA security setting, because I'm using the sites on my phone while I need to scan the QR code also using my phone... Until a site which force me to add 2FA, so I've been started to use the secret key option of the app (while I don't have to scan the QR code).

BTW, will the forum start the 2FA with the QR code one, or the forum will give the username+secret key to us to input?


Title: Re: 2FA for more security in bitcointalk forum
Post by: hilariousandco on June 29, 2015, 01:31:58 PM
If you check the forum requirements doc several different types of 2-factor have been requested.


Title: Re: 2FA for more security in bitcointalk forum
Post by: SmartIphone on June 29, 2015, 01:32:04 PM
Who says 2FA isnt good? Those who try to stole others accounts.
2FA is great.


Title: Re: 2FA for more security in bitcointalk forum
Post by: arbitrage on February 04, 2016, 11:09:11 AM
So can we expect 2fa or not?
Are there some technical disadvantages of using this?
2fa is now must have on exchanges!