Bitcoin Forum
May 25, 2024, 12:25:43 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Authorize log-in attempt by e-mail - Bitcointalk account  (Read 160 times)
bitmover (OP)
Legendary
*
Online Online

Activity: 2310
Merit: 5962


bitcoindata.science


View Profile WWW
March 23, 2018, 04:58:43 PM
 #1

Hello,

Everyday we see new topics where people complain about their hacked accounts.

As most people here earn money with their accounts, everyone should worry about account security.

Now with the implementation of the merit system our accounts are even more valuable since our hard earned merits are even more valuable than most altcoins people get from bounties.

I saw that there are already many threads asking for 2FA on your Bitcointalk. For some reason it has never been implemented.
But there are other mechanisms to increase security that can be implemented in our forum.

My suggestion is simple:
Implement a log-in authorization by e-mail every time a different IP try to login in your account.

When you try to login to your account in a different computer or network you will receive a message: "Check your e-mail to approve login attempt."

I think this simple implementation can avoid most of the related problems with hacked accounts.

Many exchanges and webwallets already use this method, so most people are quite familiar with.

What are your thoughts?

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
godzillarekt007
Full Member
***
Offline Offline

Activity: 266
Merit: 106


Floki Robot


View Profile
March 23, 2018, 05:03:20 PM
 #2

I like the idea a lot, it reminds me of how Bittrex does it when you sign in from different IP. Added bonus is because we don't have 2FA we won't have to type that code in several times before entering. 2 thumbs up idea, great way to increase security!

hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
March 23, 2018, 05:09:31 PM
 #3

There is already an authentication email sent once you try reset the password and/or change your email.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
bitperson
Full Member
***
Offline Offline

Activity: 210
Merit: 119


View Profile
March 23, 2018, 05:21:28 PM
 #4

Implement a log-in authorization by e-mail every time a different IP try to login in your account.
No! I use Bitcointalk from all over the place, so I would have to deal with such messages constantly. Sites that use them typically send them from spammy networks, so I usually have to grep through spam filter logs to find them. This is a great forum, but having to go through that kind of trouble would be too much.

How to ask questions the smart way
When you’re happy with the answers in a thread you have started, please click ‘lock topic’ to prevent spam.
1AWrZWnN4ThpGB5z24WTzsoZRMqvLpDGYU
bitmover (OP)
Legendary
*
Online Online

Activity: 2310
Merit: 5962


bitcoindata.science


View Profile WWW
March 23, 2018, 05:31:51 PM
Last edit: March 23, 2018, 11:06:16 PM by bitmover
 #5

There is already an authentication email sent once you try reset the password and/or change your email.

Thanks, I was not aware of that, as I never tried to change those.
I think it does the job.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3276
Merit: 4111


View Profile
March 24, 2018, 12:14:15 AM
 #6

I think it's best left how it is right now. Only sending notifications when details are changed on the account. Requiring a authentication email every time you log in would become very tedious. If it was optional then that would probably suit those who want extra security and those who want ease of access and not jump through loop holes every time they want to log in.
Lesbian Cow
Legendary
*
Offline Offline

Activity: 2982
Merit: 1752



View Profile
March 24, 2018, 12:36:53 AM
 #7

There is already an authentication email sent once you try reset the password and/or change your email.

How about offering 2fa on log in as a user opt in?   

To err is human, to moo is bovine

https://www.instagram.com/lesbiancow212/
actwo
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 24, 2018, 03:11:17 AM
 #8

There is already an authentication email sent once you try reset the password and/or change your email.

A hacker changed my password then my email address with out access to my email. I have sent you an PM with proof of my identity.

Thank you
jhenfelipe
Hero Member
*****
Offline Offline

Activity: 1372
Merit: 647


View Profile
March 24, 2018, 03:26:41 AM
 #9

Implement a log-in authorization by e-mail every time a different IP try to login in your account.
If there will be several options, authorization before the account will be accessed using a different device would be good too imo. A bit hassle only to those who don't have their own device to open bitcointalk.


There is already an authentication email sent once you try reset the password and/or change your email.
As announced by theymos here https://bitcointalk.org/index.php?topic=2282758.0 (if someone wants to look for it)
AzureDragon
Member
**
Offline Offline

Activity: 244
Merit: 20


View Profile
March 24, 2018, 05:51:31 AM
 #10

It seems to me that in such circumstances the developers of the forum have to seriously think about the introduction of two-factor authorization.
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
March 24, 2018, 10:16:46 AM
 #11

There is already an authentication email sent once you try reset the password and/or change your email.

A hacker changed my password then my email address with out access to my email. I have sent you an PM with proof of my identity.

Thank you

Then you should have received en email where you can lock the account. I can't do anything about restoring accounts so you'll need to PM an admin but if you haven't got a valid signed message you might as well forget about it because even accounts with them are taking months to be restored if they're being restored at all.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!