To clarify, this doesn't allow the ability to alter/change a 2fA on account by just knowing the username. In order for an account takeover to be necessary, both the username and the password need to known. This is done through brute forcing, credential stuffing, phishing attacks, and other types of malware such as clippers or cookie stealers. There are many ways your login details can become exposed on the web, and this is an entirely separate topic itself.
When you have 2fa enabled, after you enter your login details, you are presented with a screen asking for the 6-digit code which revolves in a timed rotation on your Google Authentication app. For an attacker, this is where the dead end would normally be. Without access to the device which has the authentication set up, there is nothing you should be able to do which would side step this.
This is not the case for Fortune Jack. This 2FA feature is useless if an attacker knows your login details.
Fortune Jack never responded to anything I wrote them, whether it was through a direct email, making an account on their support site, talking to their live chat, etc.
For reasons unknown to me, this is not important to Fortune Jack, as I never did, and still haven't received as much as a single word. They close my open reports with them, they respond to other people commenting on this thread, I really just do not understand it.
When a user creates a new account, the first thing you see in big, bold red letters at the top of the screen states, "DUE TO THE NATURE OF THE ONLINE GAMBLING INDUSTRY, ACCOUNT TAKEOVER IS EXTREMELY HIGH. PLEASE SETUP TWO-FACTOR-AUTHENTICATION TO ENSURE THE SAFETY OF YOUR ACCOUNT" (might not be word for word, but it is something close)
This is not any kind of bait or phishing attempt.
This can be replicated as many times as you like. If someone makes a new account (The information used can be all made up and not tied to you at all) and enables 2FA, if you supply m e with the login username and password to the account, I can have full control of the account in less than a minute.
I am more than happy to do this, and to show you that what I am saying is valid. However, if you don't want to believe what I am saying, that' 100% up to you.
I made this post to tell the players of Fortune Jack, that you are using a system with a completely flawed security practice. The company in charge of holding all your balances and account info safe, doesn't seem to give a shit. I will tell you right now though, that if you log into your account and some malicious actor drained your balances, Fortune Jack's response to this will informing you that you have two-factor authentication setup, and this ensures only YOU are able to log in to your account.
As s leading crypto casino in the world, securing company digital assets and keeping user data secure from various online threats is a top priority for us. So far, we have rolled out successful application security strategy as a defense-in-depth approach, constantly adding additional layers of protection to reduce the risks, attack surface and to prevent and detect real-time cyber attacks on the FortuneJack resources.
Especially we pay a lot of attention to ATO (Account Takeover) protection, preventing attackers from compromising user accounts through brute-force or credential stuffing attacks.
In addition, we offer multi-factor authentication (MFA) as a service for our customers, which is the top-of-the range among other solutions.
P.S - If there are any concerns regarding the MFA or account takeovers, feel free to get in touch with us. We would gladly answer all of your questions.
FJ