Bitcoin Forum
July 14, 2024, 10:28:32 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Proposal: E-mail change should require e-mail confirmation for added security  (Read 1024 times)
Boxman91 (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
September 10, 2013, 11:46:14 AM
 #1

As it stands, the e-mail address of a user can be changed with only the password of the account. This gives phishers an edge: when they get your password, they can take over the entire account.

I propose that attempting to change the e-mail address of an account should yield a confirmation e-mail to the original e-mail address, which has to be confirmed by the actual owner. This way, phishers get much less of a chance to take over the account because they would then need control over both the bitcointalk.org account, and the victims e-mail account.

With such e-mail confirmation, the owner can always recover their account.

I became victim of phishing and with no notice, the perpetrator used just my password to change my password and e-mail address, rendering me powerless to get my account back without intervention from theymos.
b!z
Legendary
*
Offline Offline

Activity: 1582
Merit: 1010



View Profile
September 10, 2013, 12:01:23 PM
 #2

I agree with this. If you are logged into someone's account, you can change the email, and password too easily. There should be confirmation or some sort of verification.
BadBear
v2.0
Legendary
*
Offline Offline

Activity: 1652
Merit: 1128



View Profile WWW
September 10, 2013, 12:01:56 PM
 #3

That would be better, at the least it would give people a heads up that there is activity unknown to them, and would save admins time.

1Kz25jm6pjNTaz8bFezEYUeBYfEtpjuKRG | PGP: B5797C4F

Tired of annoying signature ads? Ad block for signatures
tysat
Legendary
*
Offline Offline

Activity: 966
Merit: 1004


Keep it real


View Profile
September 10, 2013, 12:13:04 PM
 #4

Would probably save a lot of time for everyone, good idea!
Boxman91 (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
September 10, 2013, 12:21:00 PM
Last edit: September 10, 2013, 03:33:14 PM by Maged
 #5

Great to see people agree. I hope it's not too much of a PITA to implement such measures.

Now, not trying to be selfish, but would a mod help me out get Boxman90 back to my control, and/or tell me the procedure for this via PM as to not derail this thread? :p
Mod Note: Message sent. -Maged
Boxman90
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
September 10, 2013, 06:27:03 PM
Last edit: September 10, 2013, 10:39:40 PM by Boxman90
 #6

I disagree

This message was posted by the one who took over my account, who, surprisingly, gave it back to me. Sort of thank you, I guess?

LTC: LKKy4eDWyVtSrQAJy7Qmmz61RaFY91D9yC   BTC: 18fzdnCkuUNthCD8hM36UBGopFa9ij78gG
Peter Lambert
Hero Member
*****
Offline Offline

Activity: 756
Merit: 500

It's all fun and games until somebody loses an eye


View Profile
September 10, 2013, 06:32:38 PM
 #7

This assumes that you still have control of your old email address. What happens if you no longer have access to that email?

Use CoinBR to trade bitcoin stocks: CoinBR.com

The best place for betting with bitcoin: BitBet.us
Boxman90
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500


View Profile
September 10, 2013, 10:38:20 PM
 #8

The chances of both your e-mail address and bitcointalk account being compromized at the same time, are very small, I'd say.

LTC: LKKy4eDWyVtSrQAJy7Qmmz61RaFY91D9yC   BTC: 18fzdnCkuUNthCD8hM36UBGopFa9ij78gG
cbhelp
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
September 10, 2013, 10:40:24 PM
 #9

What?

The chances are better than they are worse, actually.
qwk
Donator
Legendary
*
Offline Offline

Activity: 3542
Merit: 3413


Shitcoin Minimalist


View Profile
September 10, 2013, 11:06:21 PM
 #10

You just gave me an idea:
https://bitcointalk.org/index.php?topic=292074.0

Yeah, well, I'm gonna go build my own blockchain. With blackjack and hookers! In fact forget the blockchain.
tysat
Legendary
*
Offline Offline

Activity: 966
Merit: 1004


Keep it real


View Profile
September 10, 2013, 11:15:50 PM
 #11

This assumes that you still have control of your old email address. What happens if you no longer have access to that email?

Then it sounds like you f'ed up, email account recovery is fairly standard.


What?

The chances are better than they are worse, actually.

Solid idea!
qwk
Donator
Legendary
*
Offline Offline

Activity: 3542
Merit: 3413


Shitcoin Minimalist


View Profile
September 10, 2013, 11:19:13 PM
 #12

Then it sounds like you f'ed up, email account recovery is fairly standard.

I once lost control of an email address because I forgot about it and cancelled the domain registration. Account recovery under those circumstances is near impossible. And worse, the new domain owner could easily steal your identity. Not that that happened a lot...

Yeah, well, I'm gonna go build my own blockchain. With blackjack and hookers! In fact forget the blockchain.
HeroC
Legendary
*
Offline Offline

Activity: 858
Merit: 1000



View Profile
September 12, 2013, 07:20:22 PM
 #13

It is a good idea in theory, but what if you no longer have access to the email? Like lavabit shutting down, you cannot access the email to confirm that you want to change your email.  Wink
tysat
Legendary
*
Offline Offline

Activity: 966
Merit: 1004


Keep it real


View Profile
September 12, 2013, 07:55:17 PM
 #14

It is a good idea in theory, but what if you no longer have access to the email? Like lavabit shutting down, you cannot access the email to confirm that you want to change your email.  Wink

You deal with the admin, I don't think it's something that will happen very often.
FeedbackLoop
Hero Member
*****
Offline Offline

Activity: 742
Merit: 500



View Profile
September 13, 2013, 04:59:20 PM
 #15

It is a good idea in theory, but what if you no longer have access to the email? Like lavabit shutting down, you cannot access the email to confirm that you want to change your email.  Wink

You deal with the admin, I don't think it's something that will happen very often.

I lost one email address once because their whole database got compromised and they decided, for the sake of their users (...), to reset all passwords and the only way they cared to send a new password was to "the secondary email" which I did not have defined. They seemed like a perfectly fine service until that very occasion.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!