Pages:
Author

Topic: 2FA to Active on Bitcointalk Forum (Requested to Admin) (Read 1581 times)

legendary
Activity: 1092
Merit: 1000
nahtnam.com
Slightly unrelated, but instead of using Google Authenticator and what not, wouldn't it be cool to have an option to sign a bitcoin address that is pre-defined as 2fa?

Two things about that:

1. Time:  with true U2F I simply touch a pad on my chip (USB A inserted in a laptop), or tap the Yubi on the back of my Android using NFC and I am in.  The second factor is virtually instant!  Computers and phones never see the keys even if infested!

2.  I will never keep my private keys on an online computer.  Never.  To sign my staked address I have to go to a cold computer because that is where the private keys are stored.

ps - side comments:  U2F is going to grow and become the standard for tons of sites anyway.  That means that serious security seekers are going to own a secure element U2F chip anyway.  Because of how the protocol operates there is no limit for how many sites you can secure using this one U2F element.  It would take me pages here to layout how this works but there are links everywhere online.  For users its "point and click" easy, and recovery codes in advance make account recovery routine!

pss - bank example:  should be the same here when U2F is implemented.  When I am logged into my bank and want to change my email or password I am stopped until I do a U2F verification.  How nice would that be here?  Nobody could mess with someone's account unless they physically held the needed U2F element OR they had the recovery codes.  No exceptions!

I agree that normal 2fa would be generally faster and more reliable, but it would still be nice to have that option. You should be able to pic. I have no problem storing my coins on my laptop, so I can sign messages on the fly.
hero member
Activity: 758
Merit: 606
Slightly unrelated, but instead of using Google Authenticator and what not, wouldn't it be cool to have an option to sign a bitcoin address that is pre-defined as 2fa?

Two things about that:

1. Time:  with true U2F I simply touch a pad on my chip (USB A inserted in a laptop), or tap the Yubi on the back of my Android using NFC and I am in.  The second factor is virtually instant!  Computers and phones never see the keys even if infested!

2.  I will never keep my private keys on an online computer.  Never.  To sign my staked address I have to go to a cold computer because that is where the private keys are stored.

ps - side comments:  U2F is going to grow and become the standard for tons of sites anyway.  That means that serious security seekers are going to own a secure element U2F chip anyway.  Because of how the protocol operates there is no limit for how many sites you can secure using this one U2F element.  It would take me pages here to layout how this works but there are links everywhere online.  For users its "point and click" easy, and recovery codes in advance make account recovery routine!

pss - bank example:  should be the same here when U2F is implemented.  When I am logged into my bank and want to change my email or password I am stopped until I do a U2F verification.  How nice would that be here?  Nobody could mess with someone's account unless they physically held the needed U2F element OR they had the recovery codes.  No exceptions!
legendary
Activity: 1092
Merit: 1000
nahtnam.com
Slightly unrelated, but instead of using Google Authenticator and what not, wouldn't it be cool to have an option to sign a bitcoin address that is pre-defined as 2fa?
hero member
Activity: 758
Merit: 606
I vote for  Google Authentication , this is really easy to use, and much safer.

Nothing is as safe as a physical key because ALL smartphone authenticator programs can be phished or worse.  Reminding you guys that security is what I do.  I have Yubikey with NFC (there are a few others around too) which is REAL U2F, and its beyond being compromised unless the stick is in your hands.  For some reading along here, but yet not familiar with U2F let me draw a parallel to the Trezors many of us use.  The software apps (like Electrum for instance) are somewhat secure.  However the software is susceptible if "cooties" are on the smartphone and things entered are being captured or re-directed.  Just like the Trezor for BTC permanently hides the keys needed to move coins, the physical U2F element never discloses its credentials to any malware infested device.  The workings are the same as a hardware wallet in that way, and they will always be a more secure process when an online device is used and especially in the hands of newbie's.

Recovery from a lost 2FA in this case is very easy for me.  I keep a spare already made up. Now if I lose, break, etc... a U2F stick I go and get my spare and immediately have access.  A lost stick means absolutely nothing unless the person holding it knows the username and password (factor one) because everything inside is encrypted to a key and cannot be opened and acquired.  So in my case there is NO person I know that has knowledge I am Coin-Keeper or that I come here.  A sign in here would NEVER happen if I were to hand the Yubi directly to the best hacker out there, because it does not link to any activity it authenticates.

For those with only one U2F key, the recovery is also super easy.  Google, Microsoft, etc.... allow you to print out recovery codes, which are lengthy and unique to use for account recovery if you lose any or all the other credentials.  Just like for those here that lose access to their accounts, if you have the recovery process prepared for in advance its a snap to get back in.  I keep several very important accounts recovery backup codes in a safe so I never have to worry about loss of a device.

If Theymos ever decides to implement U2F the process of generating recovery codes for accounts is beyond easy.  Then Theymos can forget all those I am locked out threads.  The new process could be print out your recovery codes in advance and keep them safe.  If you lose your recovery codes you lose your account.  We should be adults here.  With U2F there won't be account hacks though without serious operator errors involved.  My two cents!
member
Activity: 112
Merit: 10
I vote for  Google Authentication , this is really easy to use, and much safer.
member
Activity: 84
Merit: 10
Nimium ne crede colori
I lost my Sr.Member account today because someone hacked it and I didn't notice the hacker changed my email and password (I think I should have got a warning email or something like that).

Seems this is a must have feature, most hacks could be avoided thanks to 2FA. Admins please, take it into account!


AFAIK it's a planned feature for the new/updated/replacement forum at beta.bitcointalk.org. Of course that doesn't solve the issue here and if that replacement never comes out of beta, but, at least they're taking it into account.

That's a really good news! I advise you to activate 2FA for every account you have. It's already a standard of security in the digital world and in the next months/years adoption will grow.
PS: I personally advise you "Authy" as 2FA app; but the best 2FA is FIDO U2F/Security Keys.
member
Activity: 99
Merit: 10
I lost my Sr.Member account today because someone hacked it and I didn't notice the hacker changed my email and password (I think I should have got a warning email or something like that).

Seems this is a must have feature, most hacks could be avoided thanks to 2FA. Admins please, take it into account!


AFAIK it's a planned feature for the new/updated/replacement forum at beta.bitcointalk.org. Of course that doesn't solve the issue here and if that replacement never comes out of beta, but, at least they're taking it into account.
I didn't know.  That's definitely good news.  Thank you so much for the update.
full member
Activity: 224
Merit: 102
I lost my Sr.Member account today because someone hacked it and I didn't notice the hacker changed my email and password (I think I should have got a warning email or something like that).

Seems this is a must have feature, most hacks could be avoided thanks to 2FA. Admins please, take it into account!


AFAIK it's a planned feature for the new/updated/replacement forum at beta.bitcointalk.org. Of course that doesn't solve the issue here and if that replacement never comes out of beta, but, at least they're taking it into account.
member
Activity: 99
Merit: 10
I lost my Sr.Member account today because someone hacked it and I didn't notice the hacker changed my email and password (I think I should have got a warning email or something like that).

Seems this is a must have feature, most hacks could be avoided thanks to 2FA. Admins please, take it into account!
full member
Activity: 238
Merit: 100
I agree. Legendary accounts are very precious in this forum so if I have been promoted in that rank then I will be very worried about it getting hacked. I hope they do that next year.
full member
Activity: 182
Merit: 100
Literally everything uses 2FA these days

Not true.  My coffee maker doesn't.
I guess you're one of the few remaining WW2 Veterans? Coffee makers without 2FA haven't been made in decades.
hero member
Activity: 790
Merit: 505
2fa should have been implemented immediately after the last social engineering hack-job was done on the forum.

X
Vod
legendary
Activity: 3668
Merit: 3010
Licking my boob since 1970
Literally everything uses 2FA these days

Not true.  My coffee maker doesn't.
legendary
Activity: 3304
Merit: 3037
BTC price road to $80k
Just bumping this in hopes something gets done soon.


We've been asking for this since around 2011 or 2012 when financial transactions started happening based on forum userids. Back then, the response was that it would be incorporated into the new forum software.
As it was said everything good will be included into new forum software but that new software isn't coming and as it seems we have to wait still much.
So adding 2fa will be good to avoid so much account hacks, imagine situation of Condoras when trusted person's account was hacked and condoras lost maybe 0.4btc (can't remember).  Adding 2fa can avoid many unwanted situation.
I agree, let's add 2fa.
That was good idea to add 2fa authentication but honestly its really hard for now to access this forum and i am having issue when logging in with my account with google captcha that is why right now i just save the cookies and cache of my browser and never deleted so if this will be happen hope the google captcha can be removed and changed back to the old captcha so that i can login without having problem about my javascript  or google captcha..
full member
Activity: 182
Merit: 100
Just bumping this in hopes something gets done soon.


We've been asking for this since around 2011 or 2012 when financial transactions started happening based on forum userids. Back then, the response was that it would be incorporated into the new forum software.
Well, if nothing happens this forum will just be replaced by something better in the future. The state this place is currently in is completely unacceptable. I've literally never seen or used any place with as atrociously awful security as this forum in my 20 years on the internet.
hero member
Activity: 2268
Merit: 870
Just bumping this in hopes something gets done soon.


We've been asking for this since around 2011 or 2012 when financial transactions started happening based on forum userids. Back then, the response was that it would be incorporated into the new forum software.
As it was said everything good will be included into new forum software but that new software isn't coming and as it seems we have to wait still much.
So adding 2fa will be good to avoid so much account hacks, imagine situation of Condoras when trusted person's account was hacked and condoras lost maybe 0.4btc (can't remember).  Adding 2fa can avoid many unwanted situation.
I agree, let's add 2fa.
member
Activity: 94
Merit: 10
Just bumping this in hopes something gets done soon.


We've been asking for this since around 2011 or 2012 when financial transactions started happening based on forum userids. Back then, the response was that it would be incorporated into the new forum software.
sr. member
Activity: 467
Merit: 251
https://t.me/xwshamim
yeah i also think we at first need an email for official use . so that if any thing happens we can know through email and change every thing through email . also 2fa from google authentication is a good idea
full member
Activity: 182
Merit: 100
Just bumping this in hopes something gets done soon.

I can't believe my account got hacked without me even getting any sort of notification.
The password was safe and was definitely not spoofed elsewhere or keylogged. It was definitely obtained via a breach of this forum, which is not something that I would've expected to happen within a few weeks of updating the password. Much less with no email notification of the breach, password or email change of my account.

It's been well over two weeks with no response despite having provided ample proof of my ownership of the account as well. Either there is absolutely zero security in place, or someone with control access compromised my account, there's no other way around this case.

Very disappointed with the world's leading Bitcoin forum.
Literally everything uses 2FA these days, and no site allows users changing passwords/emails without email confirmations. The current situation is just completely unacceptable by any standards and it shines a bad light on Cryptos.

Could somebody tell me what the problem with moving to a new SMF version is?
full member
Activity: 546
Merit: 100
Question about F2A. What happens if I lose my phone. I couldn't get back into exchange because the F2A was from a different phone. Does the Goolge one get link with my email.

Can a 3rd party entity find out my email from my F2A?
As far as I know, if the phone you use for 2FA is lost you can still gain access to your account with certain requirements to prove if the account is yours. Because on an exchange that uses 2FA as well as I know it is just that and for proof it is something very difficult.

prof that if that account is yours, are totally difficult to prove. because if all of your works are only stored/access in one gadgets like a phone, all back-up and data are lost too, how could you recognize all of them when you create a proof that retrieving account is yours? its very difficult how to solve this problem. and i think there's no need to implement that 2FA here at our forum.
Pages:
Jump to: