Bitcoin Forum

Alternate cryptocurrencies => Altcoin Discussion => Topic started by: TheRealSolid on September 16, 2013, 07:25:52 AM



Title: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 07:25:52 AM
mcxNOW on September 16 had over 500 unique ips scan a 3rd party (currently unknown origin) leaked USER/PASSWORD database on the mcxNOW accounts looking for accounts which matched the leaked database. The hacker then logged into about 50 different accounts and withdrew up to 4 Bitcoins after cashing out other coins in those accounts.

Firstly
1) If you use a unique username or password at mcxNOW you have nothing to worry about.
2) If you used 2FA at mcxNOW you have nothing to worry about

Any member of mcxNOW I advise you to log in and check your security center. Look for failed logins to help identify which exchange/pool/forum database has been leaked and is being tested on sites like mcxNOW! We can then warn users of that service before the hackers take any more of these users money. Thanks.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:32:30 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: Tomatocage on September 16, 2013, 07:33:00 AM
@Coinhunter

Amazing, this happens right after you launch the new feature.

Anyone with more than two braincells not fighting each other for survival can easily this is a created situation to promote your new upgrade.

Set the fire and then be the hero that puts it our LOL

BTW, Is Solidcoin still ready for the Bitcoin collapse?


~BCX~

Holy shit you're retarded.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: prospector1 on September 16, 2013, 07:35:21 AM
^^


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: BitcoinEXpress on September 16, 2013, 07:35:31 AM
@Coinhunter

Amazing, this happens right after you launch the new feature.

Anyone with more than two braincells not fighting each other for survival can easily this is a created situation to promote your new upgrade.

Set the fire and then be the hero that puts it our LOL

BTW, Is Solidcoin still ready for the Bitcoin collapse?


~BCX~

Holy shit you're retarded.


That may be...but I'm still right  ;D ;D ;D


~BCX~


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: SuperTramp on September 16, 2013, 07:39:21 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D


mcxNOW wasn't hacked.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: ahmed_bodi on September 16, 2013, 07:40:30 AM
@Coinhunter

Amazing, this happens right after you launch the new feature.

Anyone with more than two braincells not fighting each other for survival can easily this is a created situation to promote your new upgrade.

Set the fire and then be the hero that puts it our LOL

BTW, Is Solidcoin still ready for the Bitcoin collapse?


~BCX~

Holy shit you're retarded.


That may be...but I'm still right  ;D ;D ;D


~BCX~

BCX, the attacker wasnt you by any chance? i'd like to congratulate the hacker by sending him my now stolen btc :P


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 07:44:06 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:47:44 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.



Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 07:49:19 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.



That problem relates to every exchange and service. What site doesn't suffer from it? If they have a login system it applies to them.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:50:25 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.



That problem relates to every exchange and service. What site doesn't suffer from it? If they have a login system it applies to them.

I merely think you've overstated the security of your site as "the most secure". Hard to make that statement without actual proof of 3rd party testing against/compared to other exchanges right?


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: drummerjdb666 on September 16, 2013, 07:52:34 AM
All fud aside I think the other exchange owners should keep up with this shit!!!  This is the third event I have seen in two weeks now!  


Btx  as much of an asshole as you are sir I wouldn't doubt if it was somebody like you doing this bullshit!  


It's fucking bad enough our world leaders can barely get along..


Why can't people in crypto get along either?  Why so much hate?  


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: gramma on September 16, 2013, 07:54:40 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.


Without offering any kind of position on how scam/trustworthy TheRealSolid is, I fail to see how, if my password is "password" across all of my services, and for that matter my username is "gramma", how that is MCX's failing when someone figures it out and uses it to get into it, and B of A, and Mt Gox, and and and...


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:55:21 AM
All fud aside I think the other exchange owners should keep up with this shit!!!  This is the third event I have seen in two weeks now!  


Btx  as much of an asshole as you are sir I wouldn't doubt if it was somebody like you doing this bullshit!  


It's fucking bad enough our world leaders can barely get along..


Why can't people in crypto get along either?  Why so much hate?  

I'm not condoning the "attacker" if indeed that is what happened. You need to do some reading of Coinhunter/Realsolid going back to August 2011. Come back and let's discuss.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 07:55:27 AM
I merely think you've overstated the security of your site as "the most secure". Hard to make that statement without actual proof of 3rd party testing against/compared to other exchanges right?

I coded the whole thing from scratch, including the exchange http server and had 3rd parties test it already, combined with numerous hackers testing it for the 5 months operational. It's never going to be "enough testing" in some people's minds, and it comes back to you simply not liking me boasting about something I personally think is impressive. You are free to have any opinion you want about my security and my claims, I don't judge you on it. And if you don't want to use the exchange due to it then that is your right.



Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:56:11 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.


Without offering any kind of position on how scam/trustworthy TheRealSolid is, I fail to see how, if my password is "password" across all of my services, and for that matter my username is "gramma", how that is MCX's failing when someone figures it out and uses it to get into it, and B of A, and Mt Gox, and and and...

it's not. I was merely pointing out how RS and his sockpuppets claiming mcxNOW is the "most secure" exchange ever is an OVERSTATEMENT.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 07:56:40 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

And we come back to the point that your exchange isn't the most secure given that simple fact.


Without offering any kind of position on how scam/trustworthy TheRealSolid is, I fail to see how, if my password is "password" across all of my services, and for that matter my username is "gramma", how that is MCX's failing when someone figures it out and uses it to get into it, and B of A, and Mt Gox, and and and...

Indeed and thanks to my security system at mcxNOW the people who have the same username but a different password at mcxNOW can help identify the origin of the 3rd party service which has been leaked. Hopefully we can find out soon and warn users of that site(s).


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: MarpleTrading on September 16, 2013, 07:56:45 AM
All fud aside I think the other exchange owners should keep up with this shit!!!  This is the third event I have seen in two weeks now!  


Btx  as much of an asshole as you are sir I wouldn't doubt if it was somebody like you doing this bullshit!  


It's fucking bad enough our world leaders can barely get along..


Why can't people in crypto get along either?  Why so much hate?  

It is called envy


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 07:58:13 AM
I merely think you've overstated the security of your site as "the most secure". Hard to make that statement without actual proof of 3rd party testing against/compared to other exchanges right?

I coded the whole thing from scratch, including the exchange http server and had 3rd parties test it already, combined with numerous hackers testing it for the 5 months operational. It's never going to be "enough testing" in some people's minds, and it comes back to you simply not liking me boasting about something I personally think is impressive. You are free to have any opinion you want about my security and my claims, I don't judge you on it. And if you don't want to use the exchange due to it then that is your right.



You didn't even address the part about actually comparing security tests between yours and other exchanges. Now if you had done that and a 3rd party (neutral) claimed your site as "the most secure" then fine. But until then, it is just YOUR opinion as opposed to facts that you are advertising to users.

Typical salesman tactics...


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 08:02:44 AM
You didn't even address the part about actually comparing security tests between yours and other exchanges. Now if you had done that and a 3rd party (neutral) claimed your site as "the most secure" then fine. But until then, it is just YOUR opinion as opposed to facts that you are advertising to users.

Typical salesman tactics...

Many companies/sites make claims about themselves which are very hard to verify. It is called marketing.

In this case many people who read about the security at mcxNOW and know the system do believe it is the most secure out of the systems *they know*. I am not the only one, and you can consider it an untested marketing claim / salesman tactic if you want, no one will fault you for that.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: markm on September 16, 2013, 08:03:29 AM
Can't you just make up nice long totally random passwords to people and tell them their password instead of asking them to make one up?

I guess then though they'll just go use that same one on phishingsite.com ?

-MarkM-


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: iGotSpots on September 16, 2013, 08:09:55 AM
Some of you are stupid as fuck. mcxNOW wasn't hacked. Someone got a username/password list from somewhere else and tried to log in with the list they had

Blaming RS for people being stupid and using the same name/pass for everything is even more retarded than those people are

RS shut down trading and looked into it, even though it wasn't his site that was compromised.  Holy shit people stop being so stupid


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: FrigidWinter on September 16, 2013, 08:13:34 AM
@RS,

How many threads on this topic do we need? ::)

Edit: Wasn't this the "most secure" online exchange ever? ;D

Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW. It is security 101 but some users fail to do it.

One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: drummerjdb666 on September 16, 2013, 08:16:22 AM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 08:19:28 AM
One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification

Or 2FA. The problem is these people who use the same user/pass at every site typically don't care about enabling extra security features either.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 08:20:26 AM
I admit I'm a retard but this would of at least saved me.

2FA has been there since the update too. mcxNOW doesn't store or use emails for verification but does give users the choice of Google Authenticator as a second auth device.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: iGotSpots on September 16, 2013, 08:22:48 AM
Some of you are stupid as fuck. mcxNOW wasn't hacked. Someone got a username/password list from somewhere else and tried to log in with the list they had

Blaming RS for people being stupid and using the same name/pass for everything is even more retarded than those people are

RS shut down trading and looked into it, even though it wasn't his site that was compromised.  Holy shit people stop being so stupid


Who said it was hacked?

I agree it isn't an RS issue if people were stupid enough to reuse passwords.

I just happen to like Hydrponica more than I do Realsolid/Coinhunter/Notyep/rlh


~BCX~

LOL - Yea, I know. Just responding to the people saying mcx sucks. I've been buying shares like a madman


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: FrigidWinter on September 16, 2013, 08:22:58 AM
One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification

Or 2FA. The problem is these people who use the same user/pass at every site typically don't care about enabling extra security features either.

But why do you unlike other exchanges not require email verification?

Its a major security step the "most secure" exchange should probably have


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: TheRealSolid on September 16, 2013, 08:24:12 AM
One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification

Or 2FA. The problem is these people who use the same user/pass at every site typically don't care about enabling extra security features either.

But why do you unlike other exchanges not require email verification?

Its a major security step the "most secure" exchange should probably have

I believe emails are an invasion of privacy of my users. I've removed them from the site and now will only support offline second authentication methods such as google auth.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: jdebunt on September 16, 2013, 08:47:40 AM
well my account is safe, but i'm adding google 2FA this evening just i case, meant to do it over the weekend but got caught up in things :)


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: Armchair Miner on September 16, 2013, 08:55:57 AM
Would you believe that in New York City there are actual jobs (job title "Media Relations") some of which specialize on "character assassination". Here, a character can be a person, an event, a website, or a more abstract term.

The job of these people is to twist words, and spew party line propaganda. Their job is done when sufficient number of media outlets republish their twisted words, making it "the truth".

I used to see a lot of that on Twitter, and now this thread and others are full of similar attempts.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 09:13:48 AM
Can't you just make up nice long totally random passwords to people and tell them their password instead of asking them to make one up?

I guess then though they'll just go use that same one on phishingsite.com ?

-MarkM-


I was thinking the same thing. But of course RS knows everything so I failed to mention it for that reason.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 09:15:37 AM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  

Let me ask you this: Do you know the true identity of RS?  In case he decides to close up shop and run with your coins?

BTC-e operates the same way....with anonymity.

Perhaps RS can prove me wrong and reveal his personal identity to instill trust that he could be held responsible if he ever decided to close his exchange and run with user deposits?


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 09:17:25 AM
Now we have Realsolid over on his site claiming Coinbase was the source of the leaked passwords LOL

I guess this has nothing to do with his former dislike of LTC and Coblee who works there now.

~BCX~




What I find odd is how he was such a huge hater of LTC and Coblee and now his exchange supports LTC trading. Volume on LTC as opposed to SC is huge disparity.



Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smolen on September 16, 2013, 09:20:01 AM
Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW.
Every mcxnow user has a plenty of public/private key pairs ;)


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: smoothie on September 16, 2013, 09:22:38 AM
Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW.
Every mcxnow user has a plenty of public/private key pairs ;)

Require all users to use a system generated random password of X length etc.

Done.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: drummerjdb666 on September 16, 2013, 09:33:30 AM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  

Let me ask you this: Do you know the true identity of RS?  In case he decides to close up shop and run with your coins?

BTC-e operates the same way....with anonymity.

Perhaps RS can prove me wrong and reveal his personal identity to instill trust that he could be held responsible if he ever decided to close his exchange and run with user deposits?

I'm sorry, but I have read through the old coinhunter drama..  doesn't phase me a bit.    I'm new to the community and have watched rs talk in chat for months now.  I don't believe that's going to happen, nor is it the reason for this thread.  You guys should quit trolling so damn hard.  The guy doesn't wanna tell you who he is.  Get over it.




Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: shields on September 16, 2013, 01:36:30 PM
One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification

Except if Joe-one-password is also using the same password for their email, which is not so unlikely since we already know they don't use a different password for every service.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: mistercoin on September 16, 2013, 01:57:27 PM
All fud aside I think the other exchange owners should keep up with this shit!!!  This is the third event I have seen in two weeks now!  


Btx  as much of an asshole as you are sir I wouldn't doubt if it was somebody like you doing this bullshit!  


It's fucking bad enough our world leaders can barely get along..


Why can't people in crypto get along either?  Why so much hate?  

I'm not condoning the "attacker" if indeed that is what happened. You need to do some reading of Coinhunter/Realsolid going back to August 2011. Come back and let's discuss.

+1


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: mistercoin on September 16, 2013, 02:00:36 PM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  

Let me ask you this: Do you know the true identity of RS?  In case he decides to close up shop and run with your coins?

BTC-e operates the same way....with anonymity.

Perhaps RS can prove me wrong and reveal his personal identity to instill trust that he could be held responsible if he ever decided to close his exchange and run with user deposits?

I second this. Any company that offers shares (including BTCTC) most always shows who they really are, in case of this exact reason. He could close up the site and walk away with a fortune and there would be nothing you could do about it.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 02:16:45 PM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  

Let me ask you this: Do you know the true identity of RS?  In case he decides to close up shop and run with your coins?

BTC-e operates the same way....with anonymity.

Perhaps RS can prove me wrong and reveal his personal identity to instill trust that he could be held responsible if he ever decided to close his exchange and run with user deposits?

I'm sorry, but I have read through the old coinhunter drama..  doesn't phase me a bit.    I'm new to the community and have watched rs talk in chat for months now.  I don't believe that's going to happen, nor is it the reason for this thread.  You guys should quit trolling so damn hard.  The guy doesn't wanna tell you who he is.  Get over it.




I'm sorry but you could not have possibly gotten "caught up" on reading that fast. You can't just read his posts you have to read them in context to the rest of the community at that time.

Nice try to make it seem like you're all caught up.

Your account was created on April 27, 2013. Hardly enough time to know what went on over 2 years.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: BitcoinEXpress on September 16, 2013, 02:32:31 PM
All Fear, Uncertainty, and Doubt aside.  I still feel safer with my coins on mcxNOW than a couple of other exchanges.  

Let me ask you this: Do you know the true identity of RS?  In case he decides to close up shop and run with your coins?

BTC-e operates the same way....with anonymity.

Perhaps RS can prove me wrong and reveal his personal identity to instill trust that he could be held responsible if he ever decided to close his exchange and run with user deposits?

I'm sorry, but I have read through the old coinhunter drama..  doesn't phase me a bit.    I'm new to the community and have watched rs talk in chat for months now.  I don't believe that's going to happen, nor is it the reason for this thread.  You guys should quit trolling so damn hard.  The guy doesn't wanna tell you who he is.  Get over it.




I'm sorry but you could not have possibly gotten "caught up" on reading that fast. You can't just read his posts you have to read them in context to the rest of the community at that time.

Nice try to make it seem like you're all caught up.

Your account was created on April 27, 2013. Hardly enough time to know what went on over 2 years.


Maybe he should look at the time stamp of the genesis block of Solidcoin 2 to see the maturity level of the guy. Remember, this was a coin that was ready for the collapse of bitcoin.


~BCX~


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: Disastrus on September 16, 2013, 04:51:32 PM
that RS dude is a giant twat and bi polar.
excellent material for the world nowadays...

And you have to wonder why guys like smoothie and bitcoinexpress are so determined.
I tend to believe them, because i have seen how 2 faced that Realfullofit can be.

powertripping geek.




Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: wyldfire on September 16, 2013, 04:57:22 PM
I'm not condoning the "attacker" if indeed that is what happened. You need to do some reading of Coinhunter/Realsolid going back to August 2011. Come back and let's discuss.

N00b here.  Executive summary, or links to exemplary posts?


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: smoothie on September 16, 2013, 05:00:41 PM
I'm not condoning the "attacker" if indeed that is what happened. You need to do some reading of Coinhunter/Realsolid going back to August 2011. Come back and let's discuss.

N00b here.  Executive summary, or links to exemplary posts?

https://bitcointalk.org/index.php?action=profile;u=34967;sa=showPosts


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: OnlyC on September 16, 2013, 11:26:16 PM
Why don't you add the Re-captcha to login.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: FiiNALiZE on September 16, 2013, 11:46:00 PM
Unfortunately there isn't much one can do to force users to use a unique username and password at mcxNOW.
Every mcxnow user has a plenty of public/private key pairs ;)

Require all users to use a system generated random password of X length etc.

Done.

Yeah that's a great way to scare everyone away.

No one is going to go on a site where they can't set their own passwords.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: Buffer Overflow on September 17, 2013, 12:05:44 AM
Don't these sites salt and hash passwords before being stored in their database?


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: TheFuneral on September 17, 2013, 12:25:25 AM
Now we have Realsolid over on his site claiming Coinbase was the source of the leaked passwords LOL

I guess this has nothing to do with his former dislike of LTC and Coblee who works there now.

~BCX~




do you have a script that tells you when RS posts? I'm thoroughly impressed with your response time to his postings and wish you all the best in your endeavors. Keep it up!


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: mrtchipr on September 17, 2013, 08:19:25 PM
I admit I'm a retard but this would of at least saved me.

2FA has been there since the update too. mcxNOW doesn't store or use emails for verification but does give users the choice of Google Authenticator as a second auth device.

I'm unable to setup my 2FA using Google Authenticator. I asked other users on mcxNOW chat and they told me they experience the same issue. Some recommended I try to enter the key manually instead of scanning the QR code but it still won't accept it.

Please advice what I should do.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: LiteMine on September 17, 2013, 11:56:15 PM
I admit I'm a retard but this would of at least saved me.

2FA has been there since the update too. mcxNOW doesn't store or use emails for verification but does give users the choice of Google Authenticator as a second auth device.

I'm unable to setup my 2FA using Google Authenticator. I asked other users on mcxNOW chat and they told me they experience the same issue. Some recommended I try to enter the key manually instead of scanning the QR code but it still won't accept it.

Please advice what I should do.

Had the same problem and they told me to adjust the time a little on my device (PC for me using GAuth app), because the logs said my numbers were slightly off, so it kept rejecting me. When I finally got in after about 30-40 login attempts, I just ended up withdrawing. The most disturbing part was the 30 days' wait to reset the 2FA. Now I'm sticking with Cryptsy, the SMS code to your phone works every time, so far.

Here's the email:
If you can sync the clock on your 2FA device, or as soon as the number switches you will be able to get in. There's currently no way to undo 2FA devices, the aim of them is to prevent 3rd parties entering. Other sites have a one month waiting period before resetting 2FA devices on an account. So like I said, you can mess with your time a bit and get a correct code because you're not far off it, much easier than waiting 30 days.


Title: Re: [NOTICE] mcxNOW had a leaked database run against the login system
Post by: usahero on September 18, 2013, 12:06:21 AM
I admit I'm a retard but this would of at least saved me.

2FA has been there since the update too. mcxNOW doesn't store or use emails for verification but does give users the choice of Google Authenticator as a second auth device.

I'm unable to setup my 2FA using Google Authenticator. I asked other users on mcxNOW chat and they told me they experience the same issue. Some recommended I try to enter the key manually instead of scanning the QR code but it still won't accept it.

Please advice what I should do.

Switch to white theme and scan the qr code there. If this doesn't work, then insert it manually.

Your 2fa device has to be synchronized. You do that in the settings->time correction for codes->sync now in the Google Authenticator.


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: mrtchipr on September 18, 2013, 03:58:17 PM
Thank you for the help guys.

I tried it manually and I still got the same error... but it's finally resolved!

For those of you that might find this in future, do what usahero suggested:

Your 2fa device has to be synchronized. You do that in the settings->time correction for codes->sync now in the Google Authenticator.

Thanks, you're my USA Hero ;)


Title: Re: [NOTICE] mcxNOW had a 3rd party leaked database run against the login system
Post by: TheRealSolid on September 18, 2013, 04:01:08 PM
The recent update to mcxNOW actually improved the handling of google auth 2FA. I'm a bit more lenient with 2FA devices that have wrong time. Seems many are 30 seconds behind or in front of "reality", so it should be a lot smoother with current update.