Bitcoin Forum
May 24, 2024, 06:32:49 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Is 2FA safe enough??Bad News. A guy with 2FA in Mt has been stolen for $7000+  (Read 1019 times)
cupo (OP)
Newbie
*
Offline Offline

Activity: 44
Merit: 0


View Profile
June 01, 2013, 03:58:10 AM
 #1

It's amazing that an account under 2FA in Mt.gox can be hacked. This guy found his money withdrawn on May 31, 2013. Someone changed his password and cancelled all 2FA in Security Center. He says he didn't use his mobile phone to get on Mt.gox. How did the hacker get his private key of 2FA??
It's so terrible which means the 2FA maybe not safe.

Link to this post:https://bitcointalk.org/index.php?topic=221098.0
CtrlAltBernanke420
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250


View Profile
June 01, 2013, 04:37:11 AM
 #2

It's amazing that an account under 2FA in Mt.gox can be hacked. This guy found his money withdrawn on May 31, 2013. Someone changed his password and cancelled all 2FA in Security Center. He says he didn't use his mobile phone to get on Mt.gox. How did the hacker get his private key of 2FA??
It's so terrible which means the 2FA maybe not safe.

Link to this post:https://bitcointalk.org/index.php?topic=221098.0

I wonder if that it why you also have the option to 2FA the ability to change the security settings. Which is the 3rd step.
zhcy123
Full Member
***
Offline Offline

Activity: 129
Merit: 100


View Profile
June 01, 2013, 04:41:16 AM
 #3

It's amazing that an account under 2FA in Mt.gox can be hacked. This guy found his money withdrawn on May 31, 2013. Someone changed his password and cancelled all 2FA in Security Center. He says he didn't use his mobile phone to get on Mt.gox. How did the hacker get his private key of 2FA??
It's so terrible which means the 2FA maybe not safe.

Link to this post:https://bitcointalk.org/index.php?topic=221098.0

Thank reproduced, ask for help
btbrae
Hero Member
*****
Offline Offline

Activity: 680
Merit: 500


View Profile
June 01, 2013, 05:19:09 AM
 #4

That can't be right. Why would you have the ability to enable 2FA whilst allowing someone to disable it without using 2FA? It just doesn't make sense. Surely the main added benefit of 2FA is to mitigate keylogger risk and password grabs, so you would be assuming an account can be comprised before enacting it.
Vince Torres
Sr. Member
****
Offline Offline

Activity: 337
Merit: 250


View Profile
June 01, 2013, 06:03:32 AM
 #5

I don't understand how this is possible. Did the guy have malware?

Namecoin.com .bit domain registrar. Register a new .bit domain for just $1!
BTC: 1LpKzg24NHmrxLZbnVphcstV3s7uA8cSnT
LTC: LWHswCFRPouCXTNiT8B9HUVnGrae9eojVg
cupo (OP)
Newbie
*
Offline Offline

Activity: 44
Merit: 0


View Profile
June 01, 2013, 06:45:39 AM
 #6

I don't understand how this is possible. Did the guy have malware?
Maybe there is one in his device, how to detect the malware?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!