Pages:
Author

Topic: 2FA to Active on Bitcointalk Forum (Requested to Admin) - page 2. (Read 1584 times)

member
Activity: 70
Merit: 10
Dear All,
Please request to Admin to active 2FA While Login in Bitcointalk Forum
Like : Via Email or Google Authentication !!

Thanks

 

I really dont see the need for this in addition to the one we currently have which is to a large extent has been very effective. I am also sure that when the forum administrators deemed it necessary that it should be added then they would definitely do without anyone trying to make them do it. Also, people dont go through 2FA for its sake there will be some cogent reasons and serious security challenge to make that a possibility and if its going to be implemented, then it should be made optional.

Actually you never had experienced to be attacked by hackers . many people lost the account every day .. so 2FA will help to be secured
legendary
Activity: 858
Merit: 1000
Question about F2A. What happens if I lose my phone. I couldn't get back into exchange because the F2A was from a different phone. Does the Goolge one get link with my email.

Can a 3rd party entity find out my email from my F2A?

It depends on how the service treats it. Some completely lock the account, while others let you back in if you can somehow prove your identity.
sr. member
Activity: 560
Merit: 257
Question about F2A. What happens if I lose my phone. I couldn't get back into exchange because the F2A was from a different phone. Does the Goolge one get link with my email.

Can a 3rd party entity find out my email from my F2A?
As far as I know, if the phone you use for 2FA is lost you can still gain access to your account with certain requirements to prove if the account is yours. Because on an exchange that uses 2FA as well as I know it is just that and for proof it is something very difficult.
sr. member
Activity: 308
Merit: 253
Question about F2A. What happens if I lose my phone. I couldn't get back into exchange because the F2A was from a different phone. Does the Goolge one get link with my email.

Can a 3rd party entity find out my email from my F2A?
legendary
Activity: 858
Merit: 1000
-snip-

edit: actually I see it uses CAPTCHA now on login, so that is actually a way to protect against bruteforcing.

That is a possible way, but the biggest / best CAPTCHA provider right now is Google, and it requires a JS and a bunch of other nasties the security / privacy concerned wouldn't be fond of. The new forum software will have 2fa (if it's ever released).
sr. member
Activity: 546
Merit: 250
Dear All,
Please request to Admin to active 2FA While Login in Bitcointalk Forum
Like : Via Email or Google Authentication !!

Thanks

 
Yeah I agree if you use telephone access a2f and  do not use handphone with internet, use hp like the old hp, I guess this will really keep us from thieves account and I ever experienced a theft  them trial access via email very much report of someone trying to log in, since my friend suggested using a2f on my account. and my  account secure now.
hero member
Activity: 1330
Merit: 569
Dear All,
Please request to Admin to active 2FA While Login in Bitcointalk Forum
Like : Via Email or Google Authentication !!

Thanks

 

I really dont see the need for this in addition to the one we currently have which is to a large extent has been very effective. I am also sure that when the forum administrators deemed it necessary that it should be added then they would definitely do without anyone trying to make them do it. Also, people dont go through 2FA for its sake there will be some cogent reasons and serious security challenge to make that a possibility and if its going to be implemented, then it should be made optional.
sr. member
Activity: 308
Merit: 253
It would be better than having to click on the roads and cars every time you log in.

Did something happen recently, before we could just log in entering our names and password on the top left of the page?

legendary
Activity: 1876
Merit: 1295
DiceSites.com owner
.. and NLNico had written something compatible with the version of SMF the forum uses, however it is unclear why theymos has not implemented it.

Correct.

The way I remember it, was that theymos was hoping others could give some feedback on it too. But no one did and it was never implemented :p

The package should still work fine. Although, I think it was also not good against bruteforcing, as it is using the default SMF way which isn't good.

If theymos is still interested in it, I could still add proper anti-2FA-bruteforce in that package and it can still be used :p I guess it kinda depends on when that new forum is finished too :X

edit: actually I see it uses CAPTCHA now on login, so that is actually a way to protect against bruteforcing.
full member
Activity: 357
Merit: 100
we just need fixed email to secure info , not allow change it , i think it better for all .
full member
Activity: 546
Merit: 106
Bountyhive.io
2FA should start becoming the default in all platforms theirs no reason not to have it as a function, Google Auth, Microsoft Auth, Authy, the softwares their its just for the forum and website owners to take advantage of the APIs.
copper member
Activity: 2926
Merit: 2348
email is not going to be a very useful method of 2FA (when used alone) most of the time. This is especially true considering a "real" email address is not required to register/use the forum.

Google authenticator is a better 2FA method, although it would require users to own a smartphone, which some may not. A signed message may be a good way to use 2FA, either with a Bitcoin address, or a GPG key - maybe this could be one option when the new forum is put into production.

Because Bitcointalk is an important platform of Bitcoin and Altcoin discussion so admin should take action and upgrade forum with 2FA that will help to user to be secured    
Like I said, 2fa should be implemented in the new forum.

It is difficult to implement 2fa with the version of SMF the forum is using. As posted above, theymos has said he will consider adding it someone can provide a way of adding it safely, and IIRC, a few people have posted bounties for implementing 2fa on the forum.

edit: It looks like a 2 btc bounty was offered for 2fa, and NLNico had written something compatible with the version of SMF the forum uses, however it is unclear why theymos has not implemented it.
member
Activity: 70
Merit: 10
email is not going to be a very useful method of 2FA (when used alone) most of the time. This is especially true considering a "real" email address is not required to register/use the forum.

Google authenticator is a better 2FA method, although it would require users to own a smartphone, which some may not. A signed message may be a good way to use 2FA, either with a Bitcoin address, or a GPG key - maybe this could be one option when the new forum is put into production.

Because Bitcointalk is an important platform of Bitcoin and Altcoin discussion so admin should take action and upgrade forum with 2FA that will help to user to be secured   
legendary
Activity: 2758
Merit: 6830
I'm just going to quote a reply made yesterday by actmyname about the same subject.

And just like he said, "Searching for 2FA and finding these posts took me <5 minutes."

If someone wants to write a patch for it, I will seriously consider adding it. I believe that safely adding 2FA would be very time-consuming, so I'm not willing to do it myself or direct Slickage to do it.

2FA is going to be implemented in EpochTalk. I suppose we'll all be able to use it once the forum software has been replaced:

https://github.com/slickage/epochtalk/blob/master/app/templates/login.html


Old posts but relevant.

This is also from a previously-created thread: https://bitcointalksearch.org/topic/why-doesnt-bitcointalk-support-2fa-1472714
Searching for 2FA and finding these posts took me <5 minutes.
hero member
Activity: 2044
Merit: 501
★Bitvest.io★ Play Plinko or Invest!
email is not going to be a very useful method of 2FA (when used alone) most of the time. This is especially true considering a "real" email address is not required to register/use the forum.

Google authenticator is a better 2FA method, although it would require users to own a smartphone, which some may not. A signed message may be a good way to use 2FA, either with a Bitcoin address, or a GPG key - maybe this could be one option when the new forum is put into production.

Then the forum should make a confirmation email to be considered that it is officially registered then it would be possible to use 2FA using email but I agree more via signed message since it is muh secure to use.
copper member
Activity: 2926
Merit: 2348
email is not going to be a very useful method of 2FA (when used alone) most of the time. This is especially true considering a "real" email address is not required to register/use the forum.

Google authenticator is a better 2FA method, although it would require users to own a smartphone, which some may not. A signed message may be a good way to use 2FA, either with a Bitcoin address, or a GPG key - maybe this could be one option when the new forum is put into production.
member
Activity: 70
Merit: 10
Dear All,
Please request to Admin to active 2FA While Login in Bitcointalk Forum
Like : Via Email or Google Authentication !!

Thanks

 
Pages:
Jump to: