Bitcoin Forum
April 26, 2024, 08:54:23 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: || Problem on losing/hack of accounts  (Read 250 times)
Danydee (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1248


#SWGT CERTIK Audited


View Profile WWW
November 30, 2019, 02:13:34 AM
 #1

 Just accessing the acount you can freely change the email address linked to (when knowing the password).  So that's make a situation where every Hacker if gets the password can easily and systematically appropriate the account. That's increase sinificatlly the number of hacked accounts and make the process of recovering it pretty hard.

 This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.




 

"Bitcoin: mining our own business since 2009" -- Pieter Wuille
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714121663
Hero Member
*
Offline Offline

Posts: 1714121663

View Profile Personal Message (Offline)

Ignore
1714121663
Reply with quote  #2

1714121663
Report to moderator
Gyfts
Legendary
*
Offline Offline

Activity: 2758
Merit: 1512


View Profile
November 30, 2019, 02:32:03 AM
Merited by SFR10 (1)
 #2

This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.


I imagine one of the main reasons people would change the email associated with their account would be that they don't have access to the original account which would mean this method wouldn't work.
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
November 30, 2019, 02:42:01 AM
 #3

I thought there was a cooling off period for email changes? Like 7 days or something already?

So you could lock an account if the email/password were changed.
Blacknavy
Legendary
*
Offline Offline

Activity: 1218
Merit: 1291


View Profile
November 30, 2019, 04:22:38 AM
 #4

I thought there was a cooling off period for email changes? Like 7 days or something already?

So you could lock an account if the email/password were changed.

Yes, it should be 14 days.
SFR10
Legendary
*
Offline Offline

Activity: 2982
Merit: 3409


Crypto Swap Exchange


View Profile WWW
November 30, 2019, 05:19:52 AM
 #5

This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.
"Gyfts" made a great point + 2FA [with an authenticator app] would be a better [has its own pros and cons] option and it's listed under "Planned Features" for our new forum.



█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Danydee (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1248


#SWGT CERTIK Audited


View Profile WWW
November 30, 2019, 02:08:22 PM
 #6

I thought there was a cooling off period for email changes? Like 7 days or something already?

So you could lock an account if the email/password were changed.

Yes, it should be 14 days.
I think in the minimum, Regarding the stats of login, (Device, IP, if the account just woke up ...).



This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.
"Gyfts" made a great point + 2FA [with an authenticator app] would be a better [has its own pros and cons] option and it's listed under "Planned Features" for our new forum.

  May use PGP,  or maybe just signing a btc address, asking for signing a message auto-generated from an address, no need for APP, just access to the address ..



lulucrypto
Sr. Member
****
Offline Offline

Activity: 709
Merit: 335


You need someone to develop your Web project ?


View Profile WWW
November 30, 2019, 06:37:16 PM
 #7

I imagine one of the main reasons people would change the email associated with their account would be that they don't have access to the original account which would mean this method wouldn't work.

As @Gyfts says I also think it's for those who lose access to their email, that the system works this way.

One solution would be to have some kind of retraction time ( A week ? A month ? ).
For this solution to work, it would be necessary first to send an email alert on the old email, and in the email, it would include a link to cancel the change of email.

It would not be very complicated to develop, and it will add real security in addition to the forum I think Smiley

Web developer.0x0AB75f882ef60731e02212fFcfBA7C5ce6e0B4F3
Danydee (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1248


#SWGT CERTIK Audited


View Profile WWW
November 30, 2019, 07:18:04 PM
 #8

 A month, or may more. Whatever it's more longer, it can be not enough

coupable
Hero Member
*****
Offline Offline

Activity: 2338
Merit: 757


View Profile
November 30, 2019, 07:19:12 PM
 #9

@Lulucrypto "Ownership change for accounts" works in the way you described. So it's possible to change the email if have no access to the original one, and cancel the change process using the original email if the account is compromised.
As an extra protection against any possible social engineering attacks, whenever* the administration changes an account's email address from its current value, the following process occurs:
 - The change is queued.
 - It is listed in seclog.php.
 - The old email receives a warning.
 - After 7 days, the change goes through and another seclog.php entry is added.

The account stays locked throughout all of this.

Hopefully it will be essentially unheard of, but if an account is going to be incorrectly transferred, everyone who knows about the incorrect change should noisily post all of the evidence they have so that we can at least put the change on hold and re-review the evidence.

* Admins can act outside of procedure and bypass the queue if necessary, but hardly ever will.
This system has been implemented since about a year. Not so different from the old one except about displaying data in Seclog and if your account is hacked you had 14 days to lock it through original email.
bittraffic
Hero Member
*****
Offline Offline

Activity: 2926
Merit: 612


#SWGT PRE-SALE IS LIVE


View Profile
November 30, 2019, 08:12:15 PM
 #10

This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.


I imagine one of the main reasons people would change the email associated with their account would be that they don't have access to the original account which would mean this method wouldn't work.


And this I guess the reason why posting BTC address and signing message is important for the users here. However we can also see how slow the recovering of hacked accounts. For now the only solution is to just remember your password and the address you have posted here in the forum where you can sign message, afaik ETH address right now is acceptable when you sign message.





.SWG.io.













..Pre-Sale is LIVE at $0.15..







..Buy Now..







``█████████████████▄▄
``````▄▄▄▄▄▄▄▄▄▄▄▄████▄
````````````````````▀██▄
```▀▀▀▀``▀▀▀▀▀▀▀▀▀▀▀▄███
``````▄▄▄▄▄▄▄▄▄▄▄▄``▄███
``▄▄▄▄▄▄▄```▄▄▄▄▄``▄███
``````````````````▄██▀
```````````████████████▄
````````````````````▀▀███
`````````▀▀▀▀▀▀▀▀▀▀▀▀▄████
```▄▄▄``▄▄▄▄▄▄▄▄▄▄`````███
`▄▄▄▄▄▄▄▄▄``▄▄▄▄▄▄`````███
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀████
```````````````````▄▄████
``▀▀▀▀▀``▀▀▀▀▀▀▀▀▀█████
██``███████████████▀▀

FIRST LISTING
..CONFIRMED..






Danydee (OP)
Legendary
*
Offline Offline

Activity: 2576
Merit: 1248


#SWGT CERTIK Audited


View Profile WWW
November 30, 2019, 09:27:19 PM
 #11

This can easily be palied by setting a (confirmation demand) from the existing email address, or even for emails accounts that can not longer riched/on troubles on email receiving, setting a minimum time delay before changing to the new email address.


I imagine one of the main reasons people would change the email associated with their account would be that they don't have access to the original account which would mean this method wouldn't work.


And this I guess the reason why posting BTC address and signing message is important for the users here. However we can also see how slow the recovering of hacked accounts. For now the only solution is to just remember your password and the address you have posted here in the forum where you can sign message, afaik ETH address right now is acceptable when you sign message.




(Optional) Automatic signing message verification could be great F2A option!
Imagine 'Bitcointalk' the first to do the thing Shocked

JeromeTash
Legendary
*
Offline Offline

Activity: 2128
Merit: 1210


Heisenberg


View Profile
November 30, 2019, 10:10:37 PM
 #12

I also observed the same thing when my account go hacked back in mid 2018. The person just easily changes you email address so long as they know your accounts password.

I think to avoid the problem of locking out someone from their account in case they genuinely wanted to change their email address. The email address change without authorization through the original email should be based on IP logs.

If sudden a request for an email address change was made from an unfamiliar IP address, the system would then be automatically triggered to ask the user to first authorized the email address change through a link from the original email address.


█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
coupable
Hero Member
*****
Offline Offline

Activity: 2338
Merit: 757


View Profile
November 30, 2019, 10:49:55 PM
 #13

The email address change without authorization through the original email should be based on IP logs.

If sudden a request for an email address change was made from an unfamiliar IP address, the system would then be automatically triggered to ask the user to first authorized the email address change through a link from the original email address.
This means that if i loose access to my original email i will not be able to change it. The message sent to the original email shouldn't <isn't> be for ownership change confirmation but only to cancel the change if the change is made by a hacker.
IP logs can be used to prevent hack attempts but i don't think there isn't an urgent need for it, as the actul system is working good.
lulucrypto
Sr. Member
****
Offline Offline

Activity: 709
Merit: 335


You need someone to develop your Web project ?


View Profile WWW
November 30, 2019, 11:01:25 PM
 #14

@Lulucrypto "Ownership change for accounts" works in the way you described. So it's possible to change the email if have no access to the original one, and cancel the change process using the original email if the account is compromised.
As an extra protection against any possible social engineering attacks, whenever* the administration changes an account's email address from its current value, the following process occurs:
 - The change is queued.
 - It is listed in seclog.php.
 - The old email receives a warning.
 - After 7 days, the change goes through and another seclog.php entry is added.

The account stays locked throughout all of this.

Hopefully it will be essentially unheard of, but if an account is going to be incorrectly transferred, everyone who knows about the incorrect change should noisily post all of the evidence they have so that we can at least put the change on hold and re-review the evidence.

* Admins can act outside of procedure and bypass the queue if necessary, but hardly ever will.
This system has been implemented since about a year. Not so different from the old one except about displaying data in Seclog and if your account is hacked you had 14 days to lock it through original email.

Oh, as much for me, I did not know about that.

So, if I understand ( Following the presentation of Theymos ), the process does not seem automated ?
In case of problem, we have to manually contact Theymos to trigger the process of restoration of the old ?

I am wrong ?

Web developer.0x0AB75f882ef60731e02212fFcfBA7C5ce6e0B4F3
coupable
Hero Member
*****
Offline Offline

Activity: 2338
Merit: 757


View Profile
November 30, 2019, 11:13:24 PM
 #15

Oh, as much for me, I did not know about that.

So, if I understand ( Following the presentation of Theymos ), the process does not seem automated ?
In case of problem, we have to manually contact Theymos to trigger the process of restoration of the old ?

I am wrong ?
No it's not automatic and all steps are supposed to be made manually. There is a dedicated team called "Cryptios" who is working on this with Cyrius [stuff] . Contact with them can be made using emails, they also have forum profiles but i doubt if they accept change request through forum pms.
lulucrypto
Sr. Member
****
Offline Offline

Activity: 709
Merit: 335


You need someone to develop your Web project ?


View Profile WWW
December 02, 2019, 02:36:36 AM
 #16

Oh, as much for me, I did not know about that.

So, if I understand ( Following the presentation of Theymos ), the process does not seem automated ?
In case of problem, we have to manually contact Theymos to trigger the process of restoration of the old ?

I am wrong ?
No it's not automatic and all steps are supposed to be made manually. There is a dedicated team called "Cryptios" who is working on this with Cyrius [stuff] . Contact with them can be made using emails, they also have forum profiles but i doubt if they accept change request through forum pms.

Okay, it's a shame that the process is not automated, it would not be very difficult to develop a script to automate the whole process.

After, I say that it allows to keep some control over the process, thus appearing a gain of additional security.

Web developer.0x0AB75f882ef60731e02212fFcfBA7C5ce6e0B4F3
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!