Bitcoin Forum
December 03, 2016, 07:00:16 AM *
News: To be able to use the next phase of the beta forum software, please ensure that your email address is correct/functional.
 
   Home   Help Search Donate Login Register  
Pages: « 1 [2]  All
  Print  
Author Topic: MtGox and 2 Factor Authentication  (Read 2001 times)
deego
Donator
Sr. Member
*
Offline Offline

Activity: 317


1MCoX64q6ks2Fvx8wybGYonfvEoTPpMhhR


View Profile WWW
July 14, 2012, 11:39:50 AM
 #21

Why not allow users the option of using TFA for configuring pre-set withdraw addresses. That is, make btc-withdraw *setup* part of your withdraw wizard.
 
Then, once the withdraw addresses are set up, the API could be freely used only with those withdraw addresses.

1MCoX64q6ks2Fvx8wybGYonfvEoTPpMhhR
1480748416
Hero Member
*
Offline Offline

Posts: 1480748416

View Profile Personal Message (Offline)

Ignore
1480748416
Reply with quote  #2

1480748416
Report to moderator
1480748416
Hero Member
*
Offline Offline

Posts: 1480748416

View Profile Personal Message (Offline)

Ignore
1480748416
Reply with quote  #2

1480748416
Report to moderator
1480748416
Hero Member
*
Offline Offline

Posts: 1480748416

View Profile Personal Message (Offline)

Ignore
1480748416
Reply with quote  #2

1480748416
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1480748416
Hero Member
*
Offline Offline

Posts: 1480748416

View Profile Personal Message (Offline)

Ignore
1480748416
Reply with quote  #2

1480748416
Report to moderator
jcp
Newbie
*
Offline Offline

Activity: 14


View Profile
July 14, 2012, 11:56:42 AM
 #22

We are preparing options to force delays on Bitcoins (rule set depending on aggregated 24 hours transfer amount - option configurable from the user) and emergency account lockout (that would automatically cancel any delayed transfer).

Be sure to let it be configurable to at least 72+ hours if the user so desires. In financial markets 3 days as a standard clearing time has a particular history and is a standard for many markets, probably because it's 1 full working day plus the 2 weekend days (as people do not pay close attention over the weekend).
no name
Jr. Member
*
Offline Offline

Activity: 41


View Profile
February 08, 2013, 11:49:05 AM
 #23

We are preparing options to force delays on Bitcoins (rule set depending on aggregated 24 hours transfer amount - option configurable from the user) and emergency account lockout (that would automatically cancel any delayed transfer).


bump!
kokojie
Legendary
*
Offline Offline

Activity: 1498



View Profile WWW
February 08, 2013, 02:23:43 PM
 #24

We regret to inform you that there has been another huge breach of Bitcoinica. While all passwords were changed after the theft which occurred May 11th, the password for LastPass was not compromised and thus left unchanged. The breach today occured because the password for LastPass was in fact a duplicate password which had been compromised during the hack.

Unbeknownst to us, Tihan was using the mtgox api key as the password for a website called LastPass.

Holy shit, how fucking stupid can a person be, I'd like to know what kind of fucked up logic this person used to decide that: hey I'll just use my fucking mtgox api key as my lastpass master password, which leads to ALL my other passwords. Oh and let's not change the lastpass master password, because hey there's 0.001% chance that it didn't get compromised after our first hack, so let's take that chance. Oh shit, it did get compromised in the first round of hacks, now the hacker has all the password + mtgox api key, because some fucktard decided to re-use passwords.

If my post has been helpful, send me some love -> BTC: 1kokojUapmWqCqPw3Ch2rjcVh57tJEzka | PPC: PDyXAgA8eH47gokVW6zVZPSuu15aao5nZF | Bitshares: kokojie
My reputation
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!