Pages:
Author

Topic: [BTC-TC] Virtual Community Exchange [CLOSED] - page 81. (Read 316652 times)

full member
Activity: 156
Merit: 100
Does value analysis in portfolio take into account dividends when producing overall profit/loss amounts? If not, would it be possible to incorporate that? If the work isn't worth it don't worry about it, It would be nice to see though, if it was only a couple lines of code or so. Thanks in advance Smiley
sr. member
Activity: 294
Merit: 250
Having trouble setting Google Authenticator up. Error says: "Invalid or Reused Google Auth." When I tick the box "Revoke Current Secret & Issue New Secret" the secret is not changed.
legendary
Activity: 1106
Merit: 1006
Lead Blockchain Developer
So, hypothetically, say someone forgot their PIN, is there a way for one to reset it or have it sent to their email?

Forgotten PIN resets are manual.  Wink Please submit a support request via the website.

Cheers.
sr. member
Activity: 644
Merit: 250
So, hypothetically, say someone forgot their PIN, is there a way for one to reset it or have it sent to their email?
full member
Activity: 490
Merit: 101
FRX: Ferocious Alpha
Looks great! If only TAT.VIRTUALMINE had a shorter name  Grin

Loving the ticker now, glad timestamp was added!
legendary
Activity: 1386
Merit: 1000
Looks great! If only TAT.VIRTUALMINE had a shorter name  Grin
legendary
Activity: 1106
Merit: 1006
Lead Blockchain Developer
I like the realtime widget, which is a really great addition, @burnside could you please timestamp the trades? Thanks Wink

FTFY

I could possibly timestamp them, but it'd expand the width of the window that pops out.  Anyone see any issues with this?

Also, to keep it minimalist, how's about a simple hh:mm in 24h mode?

Cheers.


I couldn't resist.  It's done now.  Note that it required a CSS change to widen the window, so you may have to purge cache or ctrl-R reload.

The times are UTC if not logged in.  If logged in it should use your selected account timezone.

Cheers.
legendary
Activity: 1946
Merit: 1035
I love it Cheesy

Wow.. burnside you are overreactive  Grin
legendary
Activity: 1106
Merit: 1006
Lead Blockchain Developer
I like the realtime widget, which is a really great addition, @burnside could you please timestamp the trades? Thanks Wink

FTFY

I could possibly timestamp them, but it'd expand the width of the window that pops out.  Anyone see any issues with this?

Also, to keep it minimalist, how's about a simple hh:mm in 24h mode?

Cheers.
legendary
Activity: 1946
Merit: 1035
I like the realtime widget, which is a really great addition, @burnside could you please timestamp the trades? Thanks Wink

FTFY

 Grin

Something like [HH:MM:SS] (B/S) # @ price STOCK-NAME
sr. member
Activity: 294
Merit: 250
http://coin.furuknap.net/
I like the realtime widget, which is a really great addition, @burnside could you please timestamp the trades? Thanks Wink

FTFY
legendary
Activity: 1946
Merit: 1035
I like the realtime widget, @burnside could you please timestamp the trades? Thanks Wink
hero member
Activity: 630
Merit: 500
Bitgoblin
Most/all banks and brokerage sites I know of do not require 2FA for their users.  It is always optional.
Most/all banks I know have 8 character passwords, useless pins as a fake primitive 2FA, and many similar practices that would make any sane developer scream.
Banks are not exactly a paragon of "doing it right". Actually they are one of the most prominent examples of "patch together some badly coded stuff, if anything breaks we don't really care".
hero member
Activity: 630
Merit: 500
Bitgoblin
you might consider offering an SMS token as google does with gmail logins
While this is a good idea in general, keep in mind that recently weird things have happened.

Until a reasonable explanation comes up for that, I wouldn't feel much safe with SMSs.
newbie
Activity: 14
Merit: 0
If you're going to do mandatory 2FA (which I agree with)
WTF.
Why would you agree with such a thing?

Some of us don't run computers infested with spywares.

Most/all banks and brokerage sites I know of do not require 2FA for their users.  It is always optional.

Most that I know of don't even provide it.  I guess they're worried about confusing the masses.  But they also have the ability to recover funds and/or undo most of the damage done after a hack.  With bitcoin the damage once done, is done.





good day, Happy to see you are addressing important issues regarding security and transparency. Also I'd like to publicly thank you for your quick response to our meta divisions' inquiries. Keep up the good work, we are especially looking forward to any updates to the NPC aspects of the game...Ira
hero member
Activity: 728
Merit: 500
If you're going to do mandatory 2FA (which I agree with)
WTF.
Why would you agree with such a thing?

Some of us don't run computers infested with spywares.

Most/all banks and brokerage sites I know of do not require 2FA for their users.  It is always optional.

Interesting. I think all major banks in the Netherlands require some form of 2FA for internet banking, but they typically provide the device required.

Even though I've not had a problem with malware or other security-matters in a decade or so, I wouldn't want to transact non-trivial amounts of funds without 2FA.
legendary
Activity: 1106
Merit: 1006
Lead Blockchain Developer
If you're going to do mandatory 2FA (which I agree with)
WTF.
Why would you agree with such a thing?

Some of us don't run computers infested with spywares.

Most/all banks and brokerage sites I know of do not require 2FA for their users.  It is always optional.

Most that I know of don't even provide it.  I guess they're worried about confusing the masses.  But they also have the ability to recover funds and/or undo most of the damage done after a hack.  With bitcoin the damage once done, is done.

sr. member
Activity: 240
Merit: 250
If you're going to do mandatory 2FA (which I agree with)
WTF.
Why would you agree with such a thing?

Some of us don't run computers infested with spywares.

Most/all banks and brokerage sites I know of do not require 2FA for their users.  It is always optional.
sr. member
Activity: 389
Merit: 250
... and this is exactly why I do not like this at all. I still need to have 2 or more computers.
That's, like, the whole point of 2FA.
I'd say using a separate program on the same machine offers some additional security over not using it at all. A simple keylogger won't compromise your account anymore, though anything that can just read the 2FA files can, but I'd hope those are less common so far.

Yeah, you do gain additional security, since many keyloggers just grab as many passwords on autopilot and that's it. However, if someone is specifically targeting you or uses a more advanced keylogger, they can access the 2FA program just as easily as your password.

Running a 2FA program on your main machine is a bit like using a Mac for security: It's not inherently more secure, but since it's less targeted by attackers, your chance of getting hit is reduced.

Yubikeys and old phones are cheap and readily available.  An old phone doesn't even need cellular service.  Just wifi to get the app installed and once it's installed, it doesn't even need that except to occasionally sync the time.  I think we're in a good place security-wise.  Where we could improve:

- One-time use form tokens.  These also prevent double button press form submission issues.  (90% done, it's in testing now.)
- 2FA input in a few places that don't already have it.  (most places that don't are not particularly sensitive.)
- Require 2FA to use the site.  Essentially no trading would be allowed until 2FA was turned on.  (still thinking this one over.)

Cheers.

Short of sending out free yubikeys for qualifying members a la MtGox I think it would be difficult to force existing 2FA, especially for new users. Incentives like existing lower trade fees should be effective and might be easy enough to tweak as required to push more adoption.
member
Activity: 106
Merit: 10

- Require 2FA to use the site.  Essentially no trading would be allowed until 2FA was turned on.  (still thinking this one over.)



If you're going to do mandatory 2FA (which I agree with), you might consider offering an SMS token as google does with gmail logins. It's probably not as secure as some other options, but any additional security that requires more than just a concurrent session is probably beneficial.

It's not entirely reasonable (just yet) to assume that everyone who may be using BTCT or LTCGlobal has a smartphone - but a mobile phone and/or yubikey requirement makes sense.
Pages:
Jump to: