THIS IS SERIOUS
If you have stocks at cryptostocks, please read.
Long story short: Our companies stock was sold at pennies and we realized that someone gained access to the CEO account, lowered the price and sold all our remaining stock for pennies and cashed out about 1 bitcoin. We could not figure out how they gained access but I just tested it and it is, in my opinion a very serious flaw yet I just got the answer from cryptostocks.com and they say it is not a flaw.... (see email below)
If someone has access to your email, despite you having 2fA set-up, they can click lost password, and then a new password link will be sent, when you click that link and make a new password, it logs you in and overrides or disables your 2FA!!!!
To me, this is an issue as our CEO felt safe since he had 2fA on but someone got into his email and that's all they needed. SECURE YOUR EMAIL WITH LONG PASSWORDS IMMEDIATELY
I emailed cryptostocks for 2 days trying to get a response about this.... first email I got was the following:
Dear user, we are have quite a backlog of emails to answer and thus please bear
with us, we will surely come back to you but this might take a few days. We hope
to have completed the backlog by latest Monday next week.Finally the addressed my concern by saying this....
Dear user, assuming that you have protected your email account (e.g. with 2FA) then this is not a flaw, you can only reset the password if you have access to the email account.
It is the same process as when you request 2FA reset (currently being implemented). We have to contact you somehow and that is by email, hence an email is send and if you click the link the 2FA will be disabled. Therefore it does not make sense to have a different approach for email resets.
==================================
Best regards
Your Cryptostocks TeamTo me, there is no reason why if you click reset password, that it should not force you to re-sign in using 2FA?
Anyone?