StevenPine (OP)
Newbie
Offline
Activity: 44
Merit: 0
|
 |
April 17, 2013, 04:35:29 AM |
|
Hi All,
I am curious what the chances are that the forum will provide optional google 2 factor authentication?
Best,
|
|
|
|
bg002h
Donator
Legendary
Offline
Activity: 1469
Merit: 1053
I outlived my lifetime membership:)
|
 |
April 17, 2013, 04:36:35 AM |
|
Not sure I'd care...
|
|
|
|
John (John K.)
Global Troll-buster and
Legendary
Offline
Activity: 1288
Merit: 1227
Away on an extended break
|
 |
April 17, 2013, 04:40:47 AM |
|
I want this feature too. I'm too paranoid to use any sites seriously without 2FA.
|
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
 |
April 17, 2013, 04:54:11 AM |
|
+1 to this too. Please don't make it too annoying, still allow remembering.
|
|
|
|
Mike Christ
aka snapsunny
Legendary
Offline
Activity: 1078
Merit: 1003
|
 |
April 17, 2013, 05:17:39 AM |
|
2FA via text would be super-duper.
|
|
|
|
|
zakoliverz
|
 |
April 17, 2013, 11:05:24 AM |
|
why would you want bitcointalk.org to get 2fa ?
|
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
 |
April 17, 2013, 11:07:04 AM |
|
Because I don't want to [buy stuff off / lend coins / etc] to a hacked account, or have people lend to me when my account is hacked?
|
|
|
|
Line
Member

Offline
Activity: 68
Merit: 10
|
 |
June 22, 2013, 04:04:48 AM |
|
This has basically become an absolute requirement at this point. Please consider implementing 2FA
|
|
|
|
Garr255
Legendary
Offline
Activity: 938
Merit: 1000
What's a GPU?
|
 |
June 22, 2013, 06:00:32 AM |
|
2fauth via MMS is simply not doable with everyone on the forum who is not in the US. Google Auth is the way to go.
|
“First they ignore you, then they laugh at you, then they fight you, then you win.” -- Mahatma Gandhi
Average time between signing on to bitcointalk: Two weeks. Please don't expect responses any faster than that!
|
|
|
Inaba
Legendary
Offline
Activity: 1260
Merit: 1000
|
 |
June 22, 2013, 06:01:12 AM |
|
Yubikey & GA. No need for silly international texts and such.
|
If you're searching these lines for a point, you've probably missed it. There was never anything there in the first place.
|
|
|
erono
|
 |
June 22, 2013, 08:21:45 AM |
|
I support 2FA .
|
|
|
|
binaryFate
Legendary
Offline
Activity: 1512
Merit: 1012
Still wild and free
|
 |
June 24, 2013, 11:44:30 AM |
|
I definitely agree. This is a must-have as large auctions and trades are taking place on the forum. Also the amount of accounts compromised greatly undermines the value of the trust network implemented (and the reliability of "reputation" in general).
|
Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. This makes Monero a better candidate to deserve the term "digital cash".
|
|
|
haveagr8day
Member

Offline
Activity: 112
Merit: 10
|
 |
June 24, 2013, 03:27:55 PM |
|
Absolutely agree, my account was hacked last night and someone posted a ton of random stuff. It would be great to have this.
|
|
|
|
ThatDGuy
|
 |
June 24, 2013, 05:17:58 PM |
|
This is a really great idea, especially given the trust that is/can be associated with these accounts.
|
|
|
|
HeroC
Legendary
Offline
Activity: 858
Merit: 1000
|
 |
June 24, 2013, 11:52:53 PM |
|
I would use it!
+1 Google Auth
I use it whenever I can!
|
|
|
|
whiskers75
|
 |
June 25, 2013, 05:23:59 PM |
|
Google Authenticator would be the way to go, maybe there is some SMF plugin.
|
|
|
|
Scott J
Legendary
Offline
Activity: 1792
Merit: 1000
|
 |
June 25, 2013, 05:26:25 PM |
|
Yes, please - why not use some of the forum's wealth to enable 2FA via SMS?
|
|
|
|
BTCOxygen
Newbie
Offline
Activity: 56
Merit: 0
|
 |
July 01, 2013, 06:05:58 PM |
|
Yes, please - why not use some of the forum's wealth to enable 2FA via SMS?
Yeah, That would be a great idea.
|
|
|
|
rme
|
 |
July 01, 2013, 06:07:06 PM |
|
Please use only Google 2FA and Yubikeys, no need for SMS.
|
|
|
|
CurbsideProphet
|
 |
July 01, 2013, 07:55:40 PM |
|
+1 for Google Authenticator
|
1ProphetnvP8ju2SxxRvVvyzCtTXDgLPJV
|
|
|
isimme
Member

Offline
Activity: 78
Merit: 10
|
 |
July 07, 2013, 07:58:42 AM |
|
Please enable 2 factor authentication?
Better yet have the option for a user to enable. If someone does not have it enabled their username shows it is not enabled maybe with a warning below their username or their username is a different color(maybe yellow for caution).
This feature would add credibility not only to individuals but to the BTC community as a whole!
|
If I was able to help you in anyway, tips are appreciated: 1A1RcqRKdApT4ViLmZcdDBES8rov3zjMYp
|
|
|
HeroC
Legendary
Offline
Activity: 858
Merit: 1000
|
 |
July 07, 2013, 03:30:54 PM |
|
Turn it into a poll.
|
|
|
|
CoinsForTech
|
 |
July 08, 2013, 12:56:26 AM |
|
+1. Very interested in using Google Authenticator on the forums
|
|
|
|
nimda
|
 |
July 08, 2013, 01:02:38 AM |
|
+1. 2FA adds a ton to security.
|
|
|
|
Evolyn
Sr. Member
  
Offline
Activity: 376
Merit: 312
Can you say... nighty-night?
|
 |
July 08, 2013, 01:31:27 AM |
|
vote for Yubikey/GA 2 FA. User using it should get an icon or something else that shows other users he/she 's using 2 FA.
I'm getting really paranoid reading about all these ppl scaming arround and then saying account was hacked.
People are f#@! d$%& stupid (this is NOT meant as insult, it includes me as well), using weak passwords, using same password everywhere, using passwords similar to their username and so on, regardless how much and often you talk about secure passwords. With 2 FA you can (partially) protect ppl from their own stupidity.
|
this signature cant be bought
|
|
|
kjj
Legendary
Offline
Activity: 1302
Merit: 1026
|
 |
July 11, 2013, 05:05:19 AM |
|
User using it should get an icon or something else that shows other users he/she 's using 2 FA.
Fuck this, and fuck google. First, you don't ever leak security state information to attackers unless you really must. Second, for a forum devoted to private money, there sure are a lot of people in this thread very eager to tell google their every move.
|
17Np17BSrpnHCZ2pgtiMNnhjnsWJ2TMqq8 I routinely ignore posters with paid advertising in their sigs. You should too.
|
|
|
Inaba
Legendary
Offline
Activity: 1260
Merit: 1000
|
 |
July 11, 2013, 05:43:35 AM |
|
Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.
|
If you're searching these lines for a point, you've probably missed it. There was never anything there in the first place.
|
|
|
kjj
Legendary
Offline
Activity: 1302
Merit: 1026
|
 |
July 11, 2013, 06:07:01 AM |
|
Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.
Have a link for that? I tried a bunch of searches looking for the technical details, but all I could find was ways to enable it on my gmail account and get SMS, so I assumed the worst.
|
17Np17BSrpnHCZ2pgtiMNnhjnsWJ2TMqq8 I routinely ignore posters with paid advertising in their sigs. You should too.
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
 |
July 11, 2013, 06:39:26 AM |
|
Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.
Have a link for that? I tried a bunch of searches looking for the technical details, but all I could find was ways to enable it on my gmail account and get SMS, so I assumed the worst. Google Auth is just a fancy name for this: function GoogleAuthenticatorCode(string secret) key := base32decode(secret) message := current Unix time ÷ 30 hash := HMAC-SHA1(key, message) offset := last nibble of hash truncatedHash := hash[offset..offset+3] //4 bytes starting at the offset Set the first bit of truncatedHash to zero //remove the most significant bit code := truncatedHash mod 1000000 pad code with 0 until length of code is 6 return code
|
|
|
|
Dougie
Full Member
 
Offline
Activity: 211
Merit: 100
You are not special.
|
 |
July 11, 2013, 07:47:13 AM |
|
I was scared by 2fa until TradeFortress pointed this out to me and sent me a javascript tool to process 2fa. I am a big advocate of it now. So yes. This is a must for this forums power users. But it should definitely be optional.
|
Lurking since 2011... 1J4DhU3q6RxxCTfAAcg5ExVK6FfxkmzkTH
|
|
|
StevenPine (OP)
Newbie
Offline
Activity: 44
Merit: 0
|
 |
July 11, 2013, 06:52:41 PM |
|
Can we get a response from a moderator or admin? The technical difficulty of installing this under options isn't that onerous.
|
|
|
|
TheButterZone
Legendary
Offline
Activity: 3052
Merit: 1033
RIP Mommy
|
 |
July 11, 2013, 11:22:26 PM |
|
Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts? If so, yes please.
|
Saying that you don't trust someone because of their behavior is completely valid.
|
|
|
binaryFate
Legendary
Offline
Activity: 1512
Merit: 1012
Still wild and free
|
 |
July 11, 2013, 11:23:51 PM |
|
Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts? If so, yes please.
Is it just my bad luck in the last few days or do you also feel a recrudescence lately?
|
Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. This makes Monero a better candidate to deserve the term "digital cash".
|
|
|
TheButterZone
Legendary
Offline
Activity: 3052
Merit: 1033
RIP Mommy
|
 |
July 11, 2013, 11:27:47 PM |
|
Heh, good word. The first one I got was June 13, now 2 separate accounts just this week.
These fucking twats would wave guns around at cops in real life... PMing me is electronic suicide. Instant trust level shitcan, instant email to the webhost of their virus, instant warning comment on the download page. They just don't learn.
|
Saying that you don't trust someone because of their behavior is completely valid.
|
|
|
binaryFate
Legendary
Offline
Activity: 1512
Merit: 1012
Still wild and free
|
 |
July 11, 2013, 11:36:01 PM |
|
Heh, good word. The first one I got was June 13, now 2 separate accounts just this week.
These fucking twats would wave guns around at cops in real life... PMing me is electronic suicide. Instant trust level shitcan, instant email to the webhost of their virus, instant warning comment on the download page. They just don't learn.
Man, I right now just got a new PM from one of these morons, and after reading your post I thought "good idea, let's leave a comment!". Then on the comment page there was already one, and it was from you. 
|
Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. This makes Monero a better candidate to deserve the term "digital cash".
|
|
|
tysat
Legendary
Offline
Activity: 966
Merit: 1004
Keep it real
|
 |
July 12, 2013, 12:11:52 AM |
|
Can we get a response from a moderator or admin? The technical difficulty of installing this under options isn't that onerous.
A response from a mod doesn't really help (as seen here). I think 2FA is a good idea, but theymos is the one who has to make it hap=pen.
|
|
|
|
theymos
Administrator
Legendary
Offline
Activity: 5502
Merit: 13915
|
 |
July 12, 2013, 01:32:15 AM |
|
Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?
No. 2FA is useless against phishing sites.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
binaryFate
Legendary
Offline
Activity: 1512
Merit: 1012
Still wild and free
|
 |
July 12, 2013, 01:35:10 AM |
|
Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?
No. 2FA is useless against phishing sites. For those phishing sites that are copy of this forum, that would be useful. Stolen passwords wouldn't be enough then, at least for people who enabled 2FA.
|
Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. This makes Monero a better candidate to deserve the term "digital cash".
|
|
|
TheButterZone
Legendary
Offline
Activity: 3052
Merit: 1033
RIP Mommy
|
 |
July 12, 2013, 05:22:58 AM |
|
Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?
No. 2FA is useless against phishing sites. For those phishing sites that are copy of this forum, that would be useful. Stolen passwords wouldn't be enough then, at least for people who enabled 2FA. I meant against the phisher account buyers themselves. Wouldn't they have to get the 2FA secret keys from the people they buy accounts from?
|
Saying that you don't trust someone because of their behavior is completely valid.
|
|
|
chsados
|
 |
July 12, 2013, 05:33:34 AM |
|
I support this tremendously.
|
|
|
|
|