Pages:
Author

Topic: 2FA for more security in bitcointalk forum (Read 1674 times)

hero member
Activity: 560
Merit: 500
February 04, 2016, 06:09:11 AM
#21
So can we expect 2fa or not?
Are there some technical disadvantages of using this?
2fa is now must have on exchanges!
legendary
Activity: 1204
Merit: 1000
Who says 2FA isnt good? Those who try to stole others accounts.
2FA is great.
global moderator
Activity: 4018
Merit: 2728
Join the world-leading crypto sportsbook NOW!
If you check the forum requirements doc several different types of 2-factor have been requested.
legendary
Activity: 3710
Merit: 1170
www.Crypto.Games: Multiple coins, multiple games
I like this idea, I use 2FA on many sites, very easy, quick and an extra layer of security.
I used to refuse any site that requires me to make a 2FA security setting, because I'm using the sites on my phone while I need to scan the QR code also using my phone... Until a site which force me to add 2FA, so I've been started to use the secret key option of the app (while I don't have to scan the QR code).

BTW, will the forum start the 2FA with the QR code one, or the forum will give the username+secret key to us to input?
legendary
Activity: 1848
Merit: 1000
I like this idea, I use 2FA on many sites, very easy, quick and an extra layer of security.
copper member
Activity: 2996
Merit: 2374
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware


A unique and complex password doesn't matter when you get a keylogger or your account taken other remotely which is what usually happens when people get their account hacked and it's easier said than done to 'Keep your computer clean from malware'. If people did then there wouldn't be an issue.
Well doing things like avoiding downloading things like QT clients of most altcoins and other random files from untrustworthy entities and to avoid going to sites that are sketchy. Using an antivirus software would probably also help. All of these practices are things that I am going to guess that many people who get malware do not follow.
global moderator
Activity: 4018
Merit: 2728
Join the world-leading crypto sportsbook NOW!
This is already planned for the new forum software , but it will be optional or obligatory ? I mean you can Unlink your account later ? then I guess selling/buying accounts will be dead since you have to give your Gmail (all google services) accounts . but most likely taking some few years since we was expecting a Beta in last December and Release on last Feb. and and it's been months and soon it will become one year .
I don't get it .. why Theymos simply don't tell us how much left so we stop asking questions and rest in peace  Embarrassed

I'm not sure if it will be obligatory or not, but if you don't use it and your account gets hacked then it should be tough luck. Theymos likely isn't going to give a date because it's hard to give one on a work in progress and if he states a deadline people will only complain when it's missed. The forum needs to be 100% working and secure and it'll take a while to iron out kinks and bugs and unexpected problems can arise so that's why it's silly giving out deadlines unless you are 100% sure.
hero member
Activity: 686
Merit: 500
This is already planned for the new forum software , but it will be optional or obligatory ? I mean you can Unlink your account later ? then I guess selling/buying accounts will be dead since you have to give your Gmail (all google services) accounts . but most likely taking some few years since we was expecting a Beta in last December and Release on last Feb. and and it's been months and soon it will become one year .
I don't get it .. why Theymos simply don't tell us how much left so we stop asking questions and rest in peace  Embarrassed
global moderator
Activity: 4018
Merit: 2728
Join the world-leading crypto sportsbook NOW!
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware


A unique and complex password doesn't matter when you get a keylogger or your account taken other remotely which is what usually happens when people get their account hacked and it's easier said than done to 'Keep your computer clean from malware'. If people did then there wouldn't be an issue.
copper member
Activity: 2996
Merit: 2374
While I do think that 2FA would overall make it more difficult to hack user's accounts, in reality, it is really not that difficult to make it difficult to secure your account, and to make it so your account will have little value in the event that it gets hacked.

All that you really need to do in order to properly secure your account is:
  • Create a unique sufficiently complex password for your account
  • Use an email that you keep similarly secure (with a different password), and whose address is not associated with your bitcointalk identity
  • Keep your computer clean from malware

All that you need in order to prevent damage from being done in the event that your account is hacked:
  • Establish a PGP key that is associated with your account, and sign all addresses that you receive payment to with that address
  • Quickly and publicly report your account as being hacked when you are unable to access it.
legendary
Activity: 1162
Merit: 1001
New forum etc etc..
full member
Activity: 144
Merit: 100
yea, adding Google 2FA (rather one-time-password) option really makes sense.  Google makes it relatively easy to implement depending on your back-end.

anyway - consider this my +1 for 2fa
legendary
Activity: 1036
Merit: 1001
/dev/null
At first I thought it would be expensive..

uhh nope, you can have it literally for free with implemented Google 2FA (Authentificator) or with possibility to add yubikey..2FA is must have for any kind of serious web service these days..

not a good idea

why? I really don't see any catch..
legendary
Activity: 1120
Merit: 1000
not a good idea

why not?

Of course not impose it to everyone, but add such option.

I don't think it would be too much compared to the 1M+ already spent in the new forum software
sr. member
Activity: 310
Merit: 256
Photon --- The First Child Of Blake Coin --Merged
not a good idea
sr. member
Activity: 462
Merit: 250
Good idea! Smiley

At first I thought it would be expensive, but as more and more sites have it implemented, it can't be that bad.
legendary
Activity: 896
Merit: 1000
Louis Vuitton
This will be an awesome option! Can't wait.
legendary
Activity: 1652
Merit: 1067
Christian Antkow
I'm sure the 2FA feature will be included in the new forums software that Theymos has spent ~$1.2M USD on, so far...
legendary
Activity: 1120
Merit: 1000
Stunna offered a bounty for whoever make 2FA avaliable in the forum, not sure if it still is up.

And if IP source verification is added I see lots of people complaining that they can't access their account because they changed their IP or tried to access the forum from some other place.


And if some people struggle to understand even how activity is calculated, I see how hard will be for them understand and configure all the auths options

global moderator
Activity: 4018
Merit: 2728
Join the world-leading crypto sportsbook NOW!
It's coming with the new forum:

https://bitcointalksearch.org/topic/current-requirements-523070

In addition to normal password authentication, the forum should support various kinds of of alternative authentication. At least password auth, email verification, secret questions, OpenID, PGP, OpenVPN (automatic creation of subnets + IP source verification), and Bitcoin address signing should be supported, with multiple allowable credentials for each auth type. Users should have the option of requiring any combination of these auth types. Like "pgp OR (password AND OpenID)". And users should be able to require that changes to some or all auth types as well as the required combination of types not take effect for some configurable number of days. This allows for different types of recovery methods.

Also, it should be possible to limit the access for each auth type. So one type might be able to only read, but not post, etc. If the Web interface uses the same API that is exposed publicly, then these permissions can be in the form of allowed API commands.
Pages:
Jump to: