Is anyone concerned, in terms of security, with the current website login of:
username:
password:
Just thinking out loud, but taking an example, let's say we know someone sent 45 BTC on or before a specific date/time. We know who it was since they posted 'whoa, I just sent 45 BTC!' here in this forum (I notice there are several members who have posted their deposit amounts looking back at the post history).
The blockchain can be easily searched for all 45 BTC transactions prior to that date (for, say, the period 2 or 3 days prior). There may be several hits, but likely not a huge number.
We know the user's bitcoinmax.com name from the forum here. We could then try a login at bitcoinmax.com using that name, and the various deposit addresses found from the blockchain that matched 45 BTC. Eventually the login would be successful and the 'imposter' would have access to the account.
I may be missing something (and I hope I am), but I'm asking for someone to convince me that the / system used by bitcoinmax.com is secure from a hack similar to what I've described above.
I already worried about the same thing.
Because I'm not (yet) able to login I don't know if the user can change the password. If you would change the password before you do an transfer it should not be a problem.
Even if someone knows your account data I'm not sure what he really can do without seeing your bitcoins...