Author

Topic: for gods sake, we need more security (Read 889 times)

legendary
Activity: 3038
Merit: 1032
RIP Mommy
March 12, 2014, 05:43:48 PM
#10
Indeed, so if you want to be spammed, you've unchecked the default setting.
administrator
Activity: 5222
Merit: 13032
March 12, 2014, 05:41:28 PM
#9
"Hide email address from public?" should be selected by default on https://bitcointalk.org/index.php?action=profile;sa=account


This has been the case since 2009...

I left the admin account set to the original SMF theme so if I somehow completely wedge the custom theme I can still get in to fix it.

I've got a neat little 12x12 coin image to replace those pip stars with.  Should look nice.  Also some nice button images to try.

The registration page has "hide your e-mail address" unchecked by default.  I must fix that in php before we can open up.

The Announcements forum is currently moderator access only.
legendary
Activity: 3038
Merit: 1032
RIP Mommy
March 12, 2014, 05:30:10 PM
#8
"Hide email address from public?" should be selected by default on https://bitcointalk.org/index.php?action=profile;sa=account
legendary
Activity: 2422
Merit: 1451
Leading Crypto Sports Betting & Casino Platform
March 12, 2014, 04:53:24 PM
#7
Also emails are accessible from the "MEMBERS" page.

https://bitcointalk.org/index.php?action=mlist

It's too damn easy for someone to create a bot and colect them all. No wonder where they got the emails for the phising.


Ignore this. Seems like Hide email address from public? is selected by default in your profile. I had forgot that.
legendary
Activity: 1162
Merit: 1001
March 12, 2014, 04:48:39 PM
#6
The last thing on the mind of the forum operator is security for its users. The end message by the staff here is WE DON'T CARE. If you lose your account or bitcoin, it's your own stupid fault.
hero member
Activity: 697
Merit: 501
March 12, 2014, 07:10:47 AM
#5
Ok that was a long read, but exactly the discussion that we need to be having.  I will be following the development closely.  Thanks for the link.
newbie
Activity: 52
Merit: 0
hero member
Activity: 697
Merit: 501
March 11, 2014, 07:26:40 AM
#3
This topic seems quite important and we should try to keep it on the first page here to get more attention.  I didn't know this about the security questions and the longer accounts are used the more valuable they are.  I don't want to lose my account.

Is the issue money or developers time??
newbie
Activity: 52
Merit: 0
March 11, 2014, 05:32:26 AM
#2
2FA would be great. GAuth is stupid easy to implement, or you could go the hosted route if you like having someone to blame.

Then again, avatars have been broken forever, so I don't think implementing new features is too high on the priority list right now.
hero member
Activity: 826
Merit: 1000
°^°
March 05, 2014, 03:22:28 PM
#1
why the hell can i just login into my account,
and change my email and security question right away?

it should at least ask for old question before changing to new,
and sending an email to the old email before you can set a new

gosh there were at least 3 accounts hacked in german sub today!
Jump to: