Bitcoin Forum

Other => New forum software => Topic started by: Coding Enthusiast on July 30, 2016, 04:46:52 PM



Title: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: Coding Enthusiast on July 30, 2016, 04:46:52 PM
i don't know if this was ever suggested or not but here is my proposal.

we have this topic (https://bitcointalk.org/index.php?topic=996318.0) with 4264 replies so far. so why not implement the ability to add bitcoin address in profile instead of secret question or as an additional option. (not talking about Bitcoin address in Forum Profile Information under Skype and things like that.)

we are on a bitcoin forum so instead of using methods that other regular forums use like secret question lets take advantage of bitcoin's features.
lets call this BTC address as recovery bitcoin address.
  • this address would be used to prove ownership of the account and it makes it easier to find since it is stored with each account information. and there is no need to go through post history to find it.
  • the only way to change it would be to sign a message from the old recovery bitcoin address so in case someone hacks the account the hacker can not change it without having access to the first recovery bitcoin address but the hacker can easily edit a forum post easily.

here is how i think it can look like in the settings  ;D



Title: Re: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: hilariousandco on July 30, 2016, 04:51:57 PM
You can already put an address in your profile but you can't really use it to recover an account. I'm not sure whether it's going to be implemented in the new forum or not but I have before suggested that any addresses that have been in your profile should be logged and mods or admins have access to that. Would help with recoveries.

Also, there will be several two factor options with the new forum so hopefully people won't have their accounts hacked in the first place.


Title: Re: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: redsn0w on July 30, 2016, 04:53:32 PM
I like the idea, +1 for me !

I think the private key of a bitcoin address is the most secure and 'secret' thing for a bitcoiner so I love the idea to recover a forum account directly using a bitcoin signed message.


Title: Re: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: Coding Enthusiast on July 30, 2016, 04:55:25 PM
@hilariousandco
but that address can easily be edited by anybody (in case of hack of course).
i am proposing a way to add a new text box for this special address apart from that bitcoin address, whoch can only be edited if you sign a message from your last special BTC address.

just like how changing password works, you enter your new password but enter your old password in order to save the changes.


Title: Re: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: KenR on July 30, 2016, 06:10:22 PM
If a hacker can access the account,what makes you think he can't simply replace the bitcoin address with the new one ? What if the user loses access to his own bitcoin address ? He will lose the account  as people would think he is a hacker.

Additionally,theymos would need to implement forum's own address sign/verifying message service if it has to happen at the backend.


Title: Re: [proposal] Stake Bitcoin address in profile setting instead of Secret Question
Post by: unamis76 on July 30, 2016, 06:54:12 PM
Excellent suggestion, I really think this should be looked at. For the new forum of course, nothing is going to be done on this one (maybe this thread would be better on the sub-forum about the new forum).

You can already put an address in your profile but you can't really use it to recover an account.

Well, you technically can (https://bitcointalk.org/index.php?topic=497545.0), but since that field can be easily changed, I assume no accounts or almost no accounts have been recovered this way.

Quote
A Bitcoin address or PGP key is associated with the account [...] if it is still listed in the account's profile.


If a hacker can access the account,what makes you think he can't simply replace the bitcoin address with the new one ? What if the user loses access to his own bitcoin address ? He will lose the account  as people would think he is a hacker.

Additionally,theymos would need to implement forum's own address sign/verifying message service if it has to happen at the backend.

Hence why the OP suggested this system, so It can be changed without the original owner signing a message from his address. If you lose access to the address, well... You can't recover the account (this is what currently happens too).