Bitcoin Forum
July 04, 2024, 06:33:37 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Secure your account  (Read 1588 times)
ndnh (OP)
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 01, 2014, 02:41:23 PM
 #1

I survived inputs.io hack, mtgox and now coinbase. (my loss less than 10% of my holdings) Here is what i do to secure an account:

I use just a complex password. no app, no 2FA, no nothing
My email address cannot be hacked using forgot my password. (even i don't remember that)
make sure u get into the real site
don't use same username or password for a trusted site and an untrusted site
use different complex password for email and other important accounts
passwords may be similar to you but inguessable for a hacker

Split your btc among different services.

vnvizow
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250



View Profile
April 01, 2014, 02:50:21 PM
 #2

Well said, captain obvious. Well, this is the Beginners & Help section......
Denni
Full Member
***
Offline Offline

Activity: 125
Merit: 100


View Profile
April 01, 2014, 02:54:28 PM
 #3

I wonder how gox hack is correlated to the password security.  Huh

lynn_402
Sr. Member
****
Offline Offline

Activity: 462
Merit: 253


View Profile
April 01, 2014, 03:20:17 PM
 #4

I survived inputs.io hack, mtgox and now coinbase. (my loss less than 10% of my holdings) Here is what i do to secure an account:

I use just a complex password. no app, no 2FA, no nothing
My email address cannot be hacked using forgot my password. (even i don't remember that)
make sure u get into the real site
don't use same username or password for a trusted site and an untrusted site
use different complex password for email and other important accounts
passwords may be similar to you but inguessable for a hacker

Split your btc among different services.



2fa is important too. With your method, you're at the mercy of keyloggers.
marcotheminer
Legendary
*
Offline Offline

Activity: 2072
Merit: 1049


┴puoʎǝq ʞool┴


View Profile
April 01, 2014, 04:41:20 PM
 #5

What the hell happened to coin base???
leex1528
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


View Profile
April 01, 2014, 04:53:41 PM
 #6

What the hell happened to coin base???

Yes, did something happen I am missing?Huh?
blacksails
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
April 01, 2014, 05:01:03 PM
 #7

My suggestion: Don't store your bitcoins online. Put them in an offline wallet where you are the only one that controls the private keys. That way you're (almost) safe from hacking (remember what Kevin Mitnick said, "No computer is ever safe.").
Shima
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
April 01, 2014, 05:11:03 PM
 #8

coinbase.com? the site is live and working fine! What had happened?
xypos
Sr. Member
****
Offline Offline

Activity: 532
Merit: 250


View Profile
April 01, 2014, 05:14:13 PM
 #9

You can have the best password and security ever, you can't do anything if the website closed (like mtgox, inputs.io, ...).
Roll Eyes
Dark.coder
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
April 01, 2014, 06:05:13 PM
 #10

No matter how secure and strong your password is you account will get hacked if you been a victim of phishing/keylogger/backdoor.
Brute forcing is quite outdated as a matter of fact unless you are using plain text/ default passwords like: Password123, admin, johnlovemarry, shane etc so its better to read and keep yourself updated regarding the new techniques and methods and prior to that using an anti virus is must. Being a security expert i strongly recommend bitdefender and malwarebytes pro.
Tip : use virustotal.com as your weapon always
MonkeyDOH
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
April 01, 2014, 06:59:57 PM
 #11

Very nicely explained ndnhc !
It's important for beginners.
NewLiberty
Legendary
*
Offline Offline

Activity: 1204
Merit: 1002


Gresham's Lawyer


View Profile WWW
April 01, 2014, 07:28:21 PM
 #12

Coinbase API allows user enumeration.
So folks can send payment requests to arbitrary users.

Here's an eli5 ish article:
http://www.cryptocoinsnews.com/news/coinbase-bug-allows-mass-phishing-and-leaked-user-information/2014/04/01

FREE MONEY1 Bitcoin for Silver and Gold NewLibertyDollar.com and now BITCOIN SPECIE (silver 1 ozt) shows value by QR
Bulk premiums as low as .0012 BTC "BETTER, MORE COLLECTIBLE, AND CHEAPER THAN SILVER EAGLES" 1Free of Government
noviapriani
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250


View Profile
April 23, 2014, 05:42:28 PM
 #13

If you login to your account on the mogstation and find the onetime password page it should be there. I believe the hardware token use the serial on the back as the emergency password instead,,,,

counter
Hero Member
*****
Offline Offline

Activity: 798
Merit: 500


Time is on our side, yes it is!


View Profile
April 23, 2014, 05:47:43 PM
 #14

Also I'd like to add that one should make sure the computer they are using to do all of this is not compromised in any way shape or form.
pekv2
Hero Member
*****
Offline Offline

Activity: 770
Merit: 502



View Profile
April 23, 2014, 11:04:22 PM
 #15

Stay safe link in my sig. Smiley Bitcoin community does a great job.
bryant.coleman
Legendary
*
Offline Offline

Activity: 3696
Merit: 1217


View Profile
April 24, 2014, 02:13:13 AM
 #16

My email address cannot be hacked using forgot my password. (even i don't remember that)

Can you tell me how did you deactivated it? Almost all the email accounts can be hacked using forgot my password, and this route is the most preferred one used by hackers to steal coins from BTC-E and other exchanges.
ndnh (OP)
Legendary
*
Offline Offline

Activity: 1302
Merit: 1005


New Decentralized Nuclear Hobbit


View Profile
April 30, 2014, 09:21:32 AM
 #17

I wonder how gox hack is correlated to the password security.  Huh

It isn't. I didn't trust it from the beginning.

coinbase.com? the site is live and working fine! What had happened?

Some coinbase accounts were hacked.
But most thought their account was hacked or something after they received a request (see http://www.reddit.com/r/Bitcoin/comments/21wyl3/coinbase_has_not_been_hacked_this_is_a_feature/)
NewLiberty is correct

My email address cannot be hacked using forgot my password. (even i don't remember that)

Can you tell me how did you deactivated it? Almost all the email accounts can be hacked using forgot my password, and this route is the most preferred one used by hackers to steal coins from BTC-E and other exchanges.
put in long string of random numbers and alohabets and symbols if there is no option to deactivate it.
Just don't forget the password Wink
BigMac
Legendary
*
Offline Offline

Activity: 896
Merit: 1000



View Profile
April 30, 2014, 11:24:48 AM
 #18

I survived inputs.io hack, mtgox and now coinbase. (my loss less than 10% of my holdings) Here is what i do to secure an account:

I use just a complex password. no app, no 2FA, no nothing
My email address cannot be hacked using forgot my password. (even i don't remember that)
make sure u get into the real site
don't use same username or password for a trusted site and an untrusted site
use different complex password for email and other important accounts
passwords may be similar to you but inguessable for a hacker

Split your btc among different services.



These are some good suggestions that everyone should take a read.

durrrr
Sr. Member
****
Offline Offline

Activity: 434
Merit: 251


View Profile
May 01, 2014, 07:55:12 PM
 #19

Is coinbase really insecure? I use authenticate for iPhone and have a good pass but was wondering if I should keep coins on there

deadley
Legendary
*
Offline Offline

Activity: 2562
Merit: 1064


View Profile
May 01, 2014, 08:24:09 PM
 #20

I setted my coinbase by sms code, without code my coinbase cant be open.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!