While I do appreciate getting a response, the only reason I took it upon myself to write this all publicly on Bitcoin Talk's board was because I could not get any kind of response when I was trying to get a hold of anyone that seemed concerned about the gravity of the situation.
My inbox is still empty from you guy though, and I don't want to waste our time having you explain to me how secure your system is, when I know beyond a shadow of a doubt, that isn't close to the truth.
Although your security practices have worked in the past, they fell short in this regard. I am concerned that you just want to list off the things you have done right, while still ignoring the things that are currently going wrong. The MFA once again does not hold much weight, seeing the nature of this exploit, and account takeovers are indeed a huge issue with this industry, which is why I would think you would rather fix the problem, rather than explain to me how their isn't one.
My main questions and concerns I have regarding 2FA related security issues, is what would be done for the players on this board if someone other broke into their account, and drained their funds because of this flaw?
Regardless if it was $20 dollars or if it was $25,000 dollars, by incorporating the 2FA features on your site, you are protecting yourselves just as much as it protects the players.
The players on your site should have the security to not have their accounts possibly in jeopardy, and they should not be subject to dealing with the after affects of having something as irreversible as a crypto payment removed from their account.
At the same time, this gives your company the protection from players who fair and square lost their bankroll, who may desperately approach you and lie about having their account breached by hackers., This shouldn't be possible with 2FA, since you need to have the physical device as well as knowing your login details.
This is only when it is working though. Right now, the tables have sharply turned against the players, because you have your entire customer base more exposed to this vulnerability / exploit
While you still are able to maintain arguments, similar to these
https://www.askgamblers.com/casino-complaints/account-hacked-2https://bitcointalksearch.org/topic/got-hacked-at-fortune-jack-934177Offer is still on the table though. Maybe a random higher ranking Bitcoin Talk user (who doesn't have an account with FJ currently) would be willing to set aside a small amount of time so I can show this to.
I have spent a lot of time on these forums, and learned a huge amount of information throughout the years on various topics. I really like this community, and I am appreciative on all the knowledge and all the insightful and nice (for the most part) users on these forums I have got to interact with over the years. I want to make it very clear that I am not brute forcing accounts, or doing any of these takeovers. I have not told anyone else this, nor do I plan on doing so.
My inbox is now able to receive PM's