Bitcoin Forum
March 21, 2025, 06:11:51 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 3 [All]
  Print  
Author Topic: Can bitcointalk.org get 2 factor authentication?  (Read 2978 times)
StevenPine (OP)
Newbie
*
Offline Offline

Activity: 44
Merit: 0


View Profile
April 17, 2013, 04:35:29 AM
 #1

Hi All,

I am curious what the chances are that the forum will provide optional google 2 factor authentication?

Best,
bg002h
Donator
Legendary
*
Offline Offline

Activity: 1469
Merit: 1053


I outlived my lifetime membership:)


View Profile WWW
April 17, 2013, 04:36:35 AM
 #2

Not sure I'd care...

Hardforks aren't that hard. It’s getting others to use them that's hard.
1GCDzqmX2Cf513E8NeThNHxiYEivU1Chhe
John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1227


Away on an extended break


View Profile
April 17, 2013, 04:40:47 AM
 #3

I want this feature too. I'm too paranoid to use any sites seriously without 2FA.
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
April 17, 2013, 04:54:11 AM
 #4

+1 to this too. Please don't make it too annoying, still allow remembering.
Mike Christ
aka snapsunny
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003



View Profile
April 17, 2013, 05:17:39 AM
 #5

2FA via text would be super-duper.

jasinlee
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500


Its as easy as 0, 1, 1, 2, 3


View Profile
April 17, 2013, 05:19:20 AM
 #6

+1

BTC 1JASiNZxmAN1WBS4dmGEDoPpzN3GV7dnjX DVC 1CxxZzqcy7YEVXfCn5KvgRxjeWvPpniK3                     Earn Devcoins Devtome.com
zakoliverz
Hero Member
*****
Offline Offline

Activity: 536
Merit: 500


View Profile
April 17, 2013, 11:05:24 AM
 #7

why would you want bitcointalk.org to get 2fa ?
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
April 17, 2013, 11:07:04 AM
 #8

Because I don't want to [buy stuff off / lend coins / etc] to a hacked account, or have people lend to me when my account is hacked?
Line
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 22, 2013, 04:04:48 AM
 #9

This has basically become an absolute requirement at this point. Please consider implementing 2FA
Garr255
Legendary
*
Offline Offline

Activity: 938
Merit: 1000


What's a GPU?


View Profile
June 22, 2013, 06:00:32 AM
 #10

2fauth via MMS is simply not doable with everyone on the forum who is not in the US. Google Auth is the way to go.

“First they ignore you, then they laugh at you, then they fight you, then you win.”  -- Mahatma Gandhi

Average time between signing on to bitcointalk: Two weeks. Please don't expect responses any faster than that!
Inaba
Legendary
*
Offline Offline

Activity: 1260
Merit: 1000



View Profile WWW
June 22, 2013, 06:01:12 AM
 #11

Yubikey & GA.  No need for silly international texts and such.


If you're searching these lines for a point, you've probably missed it.  There was never anything there in the first place.
erono
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250


View Profile
June 22, 2013, 08:21:45 AM
 #12

I support 2FA .

binaryFate
Legendary
*
Offline Offline

Activity: 1512
Merit: 1012


Still wild and free


View Profile
June 24, 2013, 11:44:30 AM
 #13

I definitely agree. This is a must-have as large auctions and trades are taking place on the forum.
Also the amount of accounts compromised greatly undermines the value of the trust network implemented (and the reliability of "reputation" in general).

Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. 
This makes Monero a better candidate to deserve the term "digital cash".
haveagr8day
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
June 24, 2013, 03:27:55 PM
 #14

Absolutely agree, my account was hacked last night and someone posted a ton of random stuff. It would be great to have this.

░▒▓█ Coinroll.it - 1% House Edge Dice Game █▓▒░ • Coinroll Thread • *FREE* 100 BTC Raffle
Tips: 14pw9gn35ueAWHvdkesQV298QLPWGBESjs
ThatDGuy
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
June 24, 2013, 05:17:58 PM
 #15

This is a really great idea, especially given the trust that is/can be associated with these accounts.
HeroC
Legendary
*
Offline Offline

Activity: 858
Merit: 1000



View Profile
June 24, 2013, 11:52:53 PM
 #16

I would use it!

+1 Google Auth

I use it whenever I can!
whiskers75
Hero Member
*****
Offline Offline

Activity: 658
Merit: 502


Doesn't use these forums that often.


View Profile
June 25, 2013, 05:23:59 PM
 #17

Google Authenticator would be the way to go, maybe there is some SMF plugin.

Elastic.pw Elastic - The Decentralized Supercomputer
ELASTIC ANNOUNCEMENT THREAD | ELASTIC SLACK | ELASTIC FORUM
Scott J
Legendary
*
Offline Offline

Activity: 1792
Merit: 1000


View Profile
June 25, 2013, 05:26:25 PM
 #18

Yes, please - why not use some of the forum's wealth to enable 2FA via SMS?
BTCOxygen
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile WWW
July 01, 2013, 06:05:58 PM
 #19

Yes, please - why not use some of the forum's wealth to enable 2FA via SMS?

Yeah, That would be a great idea.
rme
Hero Member
*****
Offline Offline

Activity: 756
Merit: 504



View Profile
July 01, 2013, 06:07:06 PM
 #20

Please use only Google 2FA and Yubikeys, no need for SMS.
CurbsideProphet
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


View Profile
July 01, 2013, 07:55:40 PM
 #21

+1 for Google Authenticator

1ProphetnvP8ju2SxxRvVvyzCtTXDgLPJV
isimme
Member
**
Offline Offline

Activity: 78
Merit: 10


View Profile
July 07, 2013, 07:58:42 AM
 #22

Please enable 2 factor authentication?

Better yet have the option for a user to enable.
If someone does not have it enabled
their username shows it is not enabled
maybe with a warning below their username or
their username is a different color(maybe yellow for caution).

This feature would add credibility not only to individuals
but to the BTC community as a whole!

If I was able to help you in anyway, tips are appreciated:
1A1RcqRKdApT4ViLmZcdDBES8rov3zjMYp
HeroC
Legendary
*
Offline Offline

Activity: 858
Merit: 1000



View Profile
July 07, 2013, 03:30:54 PM
 #23

Turn it into a poll.
CoinsForTech
Hero Member
*****
Offline Offline

Activity: 698
Merit: 500


5% Bitcoin Discount - All Orders


View Profile WWW
July 08, 2013, 12:56:26 AM
 #24

+1. Very interested in using Google Authenticator on the forums

nimda
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


0xFB0D8D1534241423


View Profile
July 08, 2013, 01:02:38 AM
 #25

+1. 2FA adds a ton to security.
Evolyn
Sr. Member
****
Offline Offline

Activity: 376
Merit: 312


Can you say... nighty-night?


View Profile
July 08, 2013, 01:31:27 AM
 #26

vote for Yubikey/GA 2 FA. User using it should get an icon or something else that shows other users he/she 's using 2 FA.

I'm getting really paranoid reading about all these ppl scaming arround and then saying account was hacked.

People are f#@! d$%& stupid (this is NOT meant as insult, it includes me as well), using weak passwords, using same password everywhere, using passwords similar to their username and so on, regardless how much and often you talk about secure passwords. With 2 FA you can (partially) protect ppl from their own stupidity.

this signature cant be bought
kjj
Legendary
*
Offline Offline

Activity: 1302
Merit: 1026



View Profile
July 11, 2013, 05:05:19 AM
 #27

User using it should get an icon or something else that shows other users he/she 's using 2 FA.

Fuck this, and fuck google.

First, you don't ever leak security state information to attackers unless you really must.  Second, for a forum devoted to private money, there sure are a lot of people in this thread very eager to tell google their every move.

17Np17BSrpnHCZ2pgtiMNnhjnsWJ2TMqq8
I routinely ignore posters with paid advertising in their sigs.  You should too.
Inaba
Legendary
*
Offline Offline

Activity: 1260
Merit: 1000



View Profile WWW
July 11, 2013, 05:43:35 AM
 #28

Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.

If you're searching these lines for a point, you've probably missed it.  There was never anything there in the first place.
kjj
Legendary
*
Offline Offline

Activity: 1302
Merit: 1026



View Profile
July 11, 2013, 06:07:01 AM
 #29

Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.

Have a link for that?  I tried a bunch of searches looking for the technical details, but all I could find was ways to enable it on my gmail account and get SMS, so I assumed the worst.

17Np17BSrpnHCZ2pgtiMNnhjnsWJ2TMqq8
I routinely ignore posters with paid advertising in their sigs.  You should too.
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
July 11, 2013, 06:39:26 AM
 #30

Except that Google Auth has nothing to do with Google's servers and you don't even need an internet connection to use it.

Have a link for that?  I tried a bunch of searches looking for the technical details, but all I could find was ways to enable it on my gmail account and get SMS, so I assumed the worst.

Google Auth is just a fancy name for this:

Quote
function GoogleAuthenticatorCode(string secret)
     key := base32decode(secret)
     message := current Unix time ÷ 30
     hash := HMAC-SHA1(key, message)
     offset := last nibble of hash
     truncatedHash := hash[offset..offset+3]  //4 bytes starting at the offset
     Set the first bit of truncatedHash to zero  //remove the most significant bit
     code := truncatedHash mod 1000000
     pad code with 0 until length of code is 6
     return code
Dougie
Full Member
***
Offline Offline

Activity: 211
Merit: 100


You are not special.


View Profile
July 11, 2013, 07:47:13 AM
 #31

I was scared by 2fa until TradeFortress pointed this out to me and sent me a javascript tool to process 2fa. I am a big advocate of it now. So yes. This is a must for this forums power users. But it should definitely be optional.

Lurking since 2011...
1J4DhU3q6RxxCTfAAcg5ExVK6FfxkmzkTH
StevenPine (OP)
Newbie
*
Offline Offline

Activity: 44
Merit: 0


View Profile
July 11, 2013, 06:52:41 PM
 #32

Can we get a response from a moderator or admin? The technical difficulty of installing this under options isn't that onerous.
TheButterZone
Legendary
*
Offline Offline

Activity: 3052
Merit: 1033


RIP Mommy


View Profile WWW
July 11, 2013, 11:22:26 PM
 #33

Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts? If so, yes please.

Saying that you don't trust someone because of their behavior is completely valid.
binaryFate
Legendary
*
Offline Offline

Activity: 1512
Merit: 1012


Still wild and free


View Profile
July 11, 2013, 11:23:51 PM
 #34

Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts? If so, yes please.

Is it just my bad luck in the last few days or do you also feel a recrudescence lately?

Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. 
This makes Monero a better candidate to deserve the term "digital cash".
TheButterZone
Legendary
*
Offline Offline

Activity: 3052
Merit: 1033


RIP Mommy


View Profile WWW
July 11, 2013, 11:27:47 PM
 #35

Heh, good word. The first one I got was June 13, now 2 separate accounts just this week.

These fucking twats would wave guns around at cops in real life... PMing me is electronic suicide. Instant trust level shitcan, instant email to the webhost of their virus, instant warning comment on the download page. They just don't learn.

Saying that you don't trust someone because of their behavior is completely valid.
binaryFate
Legendary
*
Offline Offline

Activity: 1512
Merit: 1012


Still wild and free


View Profile
July 11, 2013, 11:36:01 PM
 #36

Heh, good word. The first one I got was June 13, now 2 separate accounts just this week.

These fucking twats would wave guns around at cops in real life... PMing me is electronic suicide. Instant trust level shitcan, instant email to the webhost of their virus, instant warning comment on the download page. They just don't learn.

Man, I right now just got a new PM from one of these morons, and after reading your post I thought "good idea, let's leave a comment!". Then on the comment page there was already one, and it was from you. Cheesy

Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. 
This makes Monero a better candidate to deserve the term "digital cash".
tysat
Legendary
*
Offline Offline

Activity: 966
Merit: 1004


Keep it real


View Profile
July 12, 2013, 12:11:52 AM
 #37

Can we get a response from a moderator or admin? The technical difficulty of installing this under options isn't that onerous.

A response from a mod doesn't really help (as seen here).  I think 2FA is a good idea, but theymos is the one who has to make it hap=pen.
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5502
Merit: 13915


View Profile
July 12, 2013, 01:32:15 AM
 #38

Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?

No. 2FA is useless against phishing sites.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
binaryFate
Legendary
*
Offline Offline

Activity: 1512
Merit: 1012


Still wild and free


View Profile
July 12, 2013, 01:35:10 AM
 #39

Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?

No. 2FA is useless against phishing sites.

For those phishing sites that are copy of this forum, that would be useful. Stolen passwords wouldn't be enough then, at least for people who enabled 2FA.

Monero's privacy and therefore fungibility are MUCH stronger than Bitcoin's. 
This makes Monero a better candidate to deserve the term "digital cash".
TheButterZone
Legendary
*
Offline Offline

Activity: 3052
Merit: 1033


RIP Mommy


View Profile WWW
July 12, 2013, 05:22:58 AM
 #40

Will it stop these incessant virus PMers that seem to be trading and/or hacking forum accounts?

No. 2FA is useless against phishing sites.

For those phishing sites that are copy of this forum, that would be useful. Stolen passwords wouldn't be enough then, at least for people who enabled 2FA.


I meant against the phisher account buyers themselves. Wouldn't they have to get the 2FA secret keys from the people they buy accounts from?

Saying that you don't trust someone because of their behavior is completely valid.
chsados
Hero Member
*****
Offline Offline

Activity: 662
Merit: 545



View Profile
July 12, 2013, 05:33:34 AM
 #41

I support this tremendously.
Pages: 1 2 3 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!