Thank you for all of your quick replies,
We will start to work on the following security implementations:
1. The option to Lock your account to a specific IP
2. Required 2FA for withdrawal / optional for order execution
3. Once 2FA is enabled, you will be required to enter your 2FA to view the private key or to disable 2FA on your account.
Once again thank you for all of your support,
Havelock Investments
Good ideas. But I have lost everything. Too late for me. I knew the risks coming in. But I have just lost $50,000 + even though i had 2FA enabled
I won't bother posting again. You didn't reply to my support email so I will safely assume you aren't going to do anything to help me out.
Time to move on, out of bitcoins. The risk was always obvious. Its only when it hits you in the face your realise how real the risk is.
To repeat, I don't believe I was keylogged. Nothing else has been stolen such as other coins or paypal or bank stuff. No check I have run on my Mac suggest I have keylogging software installed. This was a very professional job from people that knew exactly how havelock worked. Not havelock employees, why would they do that? But hackers very intimate with how havelock worked.
I don't know what to say now. Its been the worst 48 hrs of my life. I'll leave it at that. Peace.
that is a unlucky thing. I wanted to transfer my derect AM shares to havelock serveral days ago,but I feel havelock is not safe enough ,so I didnt .I think havelock is lazy,it has been a long time since btct is closed and havelock became the only one stock exchange,havelock should do better
why not add the option to Lock a specific withdraw address? if want to change withdraw address need to wait 24 hours and a confirmed email ,btct had the option and I think it is good.
another problem,when I click "sign in/register" button in Havelock,it sometimes go to "Home ". the layout is bad
A few questions for Havelock:
Is your system based on a compiled language
do you use a strong encryption algorithm to store confidential information on the database
are your servers HDs encrypted
Do you have exclusive access with locks to your servers holding personal and account details
are your backups held in a secure place
Do you check IP login patterns based on geografical location
Questions for the account holder at havelock:
do you type your password every time you login
is you computer used to access your account password protected
do you always check carefully the URL when you login
has your password ever been typed or written in a computer apart from the login prompt
do you often change your password
do you use numbers and case sensitive characters for your password
When you enter your password do you make sure nobody is looking over your shoulder.
If all answers are yes it would be quite hard for anyone to break in any account, or an inside job by somebody with access to the servers such as havelock employees or cleaners, or people handling the backups or the servers.