Bitcoin Forum
June 23, 2024, 11:22:08 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: Major Flaw in Security  (Read 5357 times)
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3850
Merit: 2647


Join the world-leading crypto sportsbook NOW!


View Profile
December 27, 2014, 12:46:37 PM
 #41

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 27, 2014, 12:47:49 PM
 #42

How about the option of 3-factor?  Cheesy. Google auth would be better than email but both are only as secure as you are. Email is probably much easier to hack, but couldn't you reset google auth via email?

The Google Authenticator keys are stored on your device, not on a Google server. This means that a potential hacker needs access and control of your device. So pay attention while browsing, downloading etc. anything with your mobile phone.
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
December 27, 2014, 01:03:11 PM
 #43

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.
Contact the support and get your account back. Authy binds the 2FA to your phone numbers. You would need to reset the phone using your email and key in your password and you would gain access to your 2FAs. It isnt hard to get a new sim card for your phone number. This kind of 2FA can be a bit dangerous compared to google authenticator.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
December 27, 2014, 01:08:22 PM
 #44

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.
Contact the support and get your account back. Authy binds the 2FA to your phone numbers. You would need to reset the phone using your email and key in your password and you would gain access to your 2FAs. It isnt hard to get a new sim card for your phone number. This kind of 2FA can be a bit dangerous compared to google authenticator.

The email + 2FA is the best solution in my opinion. I think the email verification is easy to add here in the forum, but theymos don't want (or am I wrong ?).
ranochigo
Legendary
*
Offline Offline

Activity: 2982
Merit: 4193



View Profile
December 27, 2014, 01:19:28 PM
 #45

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.
Contact the support and get your account back. Authy binds the 2FA to your phone numbers. You would need to reset the phone using your email and key in your password and you would gain access to your 2FAs. It isnt hard to get a new sim card for your phone number. This kind of 2FA can be a bit dangerous compared to google authenticator.

The email + 2FA is the best solution in my opinion. I think the email verification is easy to add here in the forum, but theymos don't want (or am I wrong ?).
Well i'm not pretty sure about him wanting to add the 2 factor but i think its included in the upcoming forum upgrade. He would have to redesign the login page to include two factor and have to make modifications to the database to include 2FA as the SMF for this version didnt include 2FA. Please correct me if im wrong.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1042


#Free market


View Profile
December 27, 2014, 01:23:57 PM
 #46

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.
Contact the support and get your account back. Authy binds the 2FA to your phone numbers. You would need to reset the phone using your email and key in your password and you would gain access to your 2FAs. It isnt hard to get a new sim card for your phone number. This kind of 2FA can be a bit dangerous compared to google authenticator.

The email + 2FA is the best solution in my opinion. I think the email verification is easy to add here in the forum, but theymos don't want (or am I wrong ?).
Well i'm not pretty sure about him wanting to add the 2 factor but i think its included in the upcoming forum upgrade. He would have to redesign the login page to include two factor and have to make modifications to the database to include 2FA as the SMF for this version didnt include 2FA. Please correct me if im wrong.


Problem solved :  https://bitcointalk.org/index.php?topic=364307.msg7733979#msg7733979    It takes  only a few changes and it is  ready for the bitcointalk forum.
LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
December 27, 2014, 01:39:32 PM
 #47

What if you lose your phone? I'm sure I read there's alternative ways to restore access to it if you lose it.
Contact the support and get your account back. Authy binds the 2FA to your phone numbers. You would need to reset the phone using your email and key in your password and you would gain access to your 2FAs. It isnt hard to get a new sim card for your phone number. This kind of 2FA can be a bit dangerous compared to google authenticator.

The email + 2FA is the best solution in my opinion. I think the email verification is easy to add here in the forum, but theymos don't want (or am I wrong ?).
Well i'm not pretty sure about him wanting to add the 2 factor but i think its included in the upcoming forum upgrade. He would have to redesign the login page to include two factor and have to make modifications to the database to include 2FA as the SMF for this version didnt include 2FA. Please correct me if im wrong.


Problem solved :  https://bitcointalk.org/index.php?topic=364307.msg7733979#msg7733979    It takes  only a few changes and it is  ready for the bitcointalk forum.

The problem is that addons can always be a potential security risk. But it's great and I hope the bounty of Stunna gets fulfilled soon Wink
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
December 27, 2014, 03:25:36 PM
 #48

How about the option of 3-factor?  Cheesy. Google auth would be better than email but both are only as secure as you are. Email is probably much easier to hack, but couldn't you reset google auth via email?
Why not? The more the better if you ask me.
Google auth isn't a risk at all if used correctly. Why not buy an smartphone from a Chinese manufacturer (very cheap) and use it only for auth? Your device won't get hacked I'm sure.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3850
Merit: 2647


Join the world-leading crypto sportsbook NOW!


View Profile
December 27, 2014, 03:39:49 PM
 #49

How about the option of 3-factor?  Cheesy. Google auth would be better than email but both are only as secure as you are. Email is probably much easier to hack, but couldn't you reset google auth via email?
Why not? The more the better if you ask me.

I actually agree. More would make me feel more secure but it could also lead to more problems. People will likely complain if they lose access to their 2-factor and then pester theymos to remove them which if he does it's not very secure and if he doesn't then their accounts are screwed. Always going to be a catch 22.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
December 27, 2014, 05:47:15 PM
 #50

How about the option of 3-factor?  Cheesy. Google auth would be better than email but both are only as secure as you are. Email is probably much easier to hack, but couldn't you reset google auth via email?
Why not? The more the better if you ask me.

I actually agree. More would make me feel more secure but it could also lead to more problems. People will likely complain if they lose access to their 2-factor and then pester theymos to remove them which if he does it's not very secure and if he doesn't then their accounts are screwed. Always going to be a catch 22.
That's their problem and theymos shouldn't do anything about it. I have even registered on a few sites which state that password recovery is not possible, even if you contact support.
Every single member is obligated to know their password/or in this instance their 2/3-factor.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
marcotheminer (OP)
Legendary
*
Offline Offline

Activity: 2072
Merit: 1049


┴puoʎǝq ʞool┴


View Profile
February 24, 2015, 02:16:10 PM
 #51

Bump.
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!