misterbigg (OP)
Legendary
Offline
Activity: 1064
Merit: 1001
|
|
August 03, 2012, 02:49:49 PM Last edit: August 03, 2012, 03:07:29 PM by misterbigg |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
|
|
|
|
kiba
Legendary
Offline
Activity: 980
Merit: 1020
|
|
August 03, 2012, 02:54:36 PM |
|
You shouldn't call it a scam based on merely bad security practice.
|
|
|
|
BadBear
v2.0
Legendary
Offline
Activity: 1652
Merit: 1128
|
|
August 03, 2012, 02:55:26 PM |
|
That doesn't make it a scam...
|
|
|
|
URSAY
Legendary
Offline
Activity: 1974
Merit: 1010
|
|
August 03, 2012, 02:57:08 PM |
|
EVERYONE IS A SCAM.
|
|
|
|
John (John K.)
Global Troll-buster and
Legendary
Offline
Activity: 1288
Merit: 1227
Away on an extended break
|
|
August 03, 2012, 02:58:09 PM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
Uh, I think rewording 'scam' to sloppy would be better in this case.
|
|
|
|
Stephen Gornick
Legendary
Offline
Activity: 2506
Merit: 1010
|
|
August 03, 2012, 05:50:35 PM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
They have two-factor authentication (using SMS text messaging).
|
|
|
|
finkleshnorts
|
|
August 03, 2012, 05:52:50 PM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
Uh, I think rewording 'scam' to sloppy would be better in this case. CampBX is a sloppy?
|
|
|
|
John (John K.)
Global Troll-buster and
Legendary
Offline
Activity: 1288
Merit: 1227
Away on an extended break
|
|
August 04, 2012, 02:09:40 AM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
Uh, I think rewording 'scam' to sloppy would be better in this case. CampBX is a sloppy? Oops, forgot about the a. Make it rewording 'a scam' to 'sloppy' instead.
|
|
|
|
Littleshop
Legendary
Offline
Activity: 1386
Merit: 1004
|
|
August 06, 2012, 02:42:37 AM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
They have two-factor authentication (using SMS text messaging). I asked for this, they said it is not available currently though soon it should be. Does anyone have this working?
|
|
|
|
Stephen Gornick
Legendary
Offline
Activity: 2506
Merit: 1010
|
|
August 06, 2012, 10:35:01 PM |
|
I asked for this, they said it is not available currently though soon it should be. Does anyone have this working?
Are you outside the U.S.?
|
|
|
|
URSAY
Legendary
Offline
Activity: 1974
Merit: 1010
|
|
August 06, 2012, 10:49:33 PM |
|
I've used Camp BX a few times. It was quick and easy. Thanks Camp BX!
|
|
|
|
smoothie
Legendary
Offline
Activity: 2492
Merit: 1474
LEALANA Bitcoin Grim Reaper
|
|
August 07, 2012, 02:56:36 AM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
Really? So not only do you have to keep your password super secret you have to keep your username super extra mega secret? Wow...just .... wow... These guys were on "the bitcoin show" .... No wonder...
|
███████████████████████████████████████
,╓p@@███████@╗╖, ,p████████████████████N, d█████████████████████████b d██████████████████████████████æ ,████²█████████████████████████████, ,█████ ╙████████████████████╨ █████y ██████ `████████████████` ██████ ║██████ Ñ███████████` ███████ ███████ ╩██████Ñ ███████ ███████ ▐▄ ²██╩ a▌ ███████ ╢██████ ▐▓█▄ ▄█▓▌ ███████ ██████ ▐▓▓▓▓▌, ▄█▓▓▓▌ ██████─ ▐▓▓▓▓▓▓█,,▄▓▓▓▓▓▓▌ ▐▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▌ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓─ ²▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓╩ ▀▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀ ²▀▀▓▓▓▓▓▓▓▓▓▓▓▓▀▀` ²²² ███████████████████████████████████████
| . ★☆ WWW.LEALANA.COM My PGP fingerprint is A764D833. History of Monero development Visualization ★☆ . LEALANA BITCOIN GRIM REAPER SILVER COINS. |
|
|
|
Keyur @ Camp BX
|
|
August 07, 2012, 07:23:15 PM |
|
For a company that tries to position itself as a "Trusted Bitcoin Platform", I find these facts disturbing:
- Anyone can reset anyone else's password by knowing their user name
- The "change password" form only has one field for "New Password" instead of two, allowing for user error.
Hi Bigg, I would like to clarify that this was never a security risk as the password goes to the original registered email address, and not displayed on screen. Worst case scenario is that someone with too much time on their hands can annoy you with repeat password resets. Point noted though - we are reworking the PW reset code to be annoyance-proof and will deploy the update shortly. - Keyur
|
|
|
|
misterbigg (OP)
Legendary
Offline
Activity: 1064
Merit: 1001
|
|
August 19, 2012, 12:16:21 AM |
|
I would like to clarify that this was never a security risk as the password goes to the original registered email address, and not displayed on screen. The fact is that a programmer implemented the password reset incorrectly. Whoever was writing the code should have known better - this points to a management problem. It's a rookie mistake. If a visible rookie mistake like this is possible at CampBX, who knows what other invisible mistakes were made?
|
|
|
|
URSAY
Legendary
Offline
Activity: 1974
Merit: 1010
|
|
August 22, 2012, 02:19:59 PM |
|
I've been waiting for 48 hours on a support response of any kind. How long do they usually take?
|
|
|
|
URSAY
Legendary
Offline
Activity: 1974
Merit: 1010
|
|
August 22, 2012, 06:23:52 PM |
|
Just heard back from Camp BX. Issue resolved. Another win for Camp BX. Thanks!
|
|
|
|
|
em23black
Newbie
Offline
Activity: 3
Merit: 0
|
|
March 10, 2014, 02:21:17 AM |
|
|
|
|
|
|