Pages:
Author

Topic: mcx passwords - page 4. (Read 4339 times)

full member
Activity: 196
Merit: 100
August 08, 2013, 04:28:24 PM
#13
I think racism is bad yes go read the chat there its non stop race bashing, peoples religion, holocaust jokes etc, lots of hate unprofessional all around.

member
Activity: 60
Merit: 10
August 08, 2013, 04:16:21 PM
#12

The proof is ask RS for your password and he can give it to you been that way for a while so that is proof. Even if he changes it he has a great record of usernames and passwords to skim from pools and exchanges for the folks not smart enough to change their passwords site by site. Lets get serious the site is full of hate speech racism, sexism just an all around bad environment. The owner is a straight up psychopath and very full of himself. C++ will solve cancer!

I will start posting chat logs from there just to show the enormous amount of hate mongering going on with this exchange but I think enough folks can vouch for that.


I think racism is bad yes go read the chat there its non stop race bashing, peoples religion, holocaust jokes etc, lots of hate unprofessional all around.


Quote
1) For the sake of argument let's say RS is using plaint text passwords and can see them

So fucking what, if a person in the altcoin world is STUPID enough to use the same password on two different sites, they deserve to be ripped off. So basically by following password 101, all RS could do if see the password for his own site.

2) mcxNOW does not use plain text, this is straight up fud.

3) Coinhunter is telling the truth, he's banned only four people from mcxNOW and you're 25% of that population, that makes you special.

4) You are correct, CH/RS is a real piece of work, a meglomaniacal narcissistic POS, but what you're doing isn't promoting that idea, it's just making you look like a stupid fuck.


~BCX~

I don't disagree that it is insane to have the same passwords for any crypto site but they do. On that note has anyone asked for their passwords yet?

These are facts go see for yourself oh and buy some shares of the biggest scam around.
full member
Activity: 196
Merit: 100
August 08, 2013, 03:55:38 PM
#11

The proof is ask RS for your password and he can give it to you been that way for a while so that is proof. Even if he changes it he has a great record of usernames and passwords to skim from pools and exchanges for the folks not smart enough to change their passwords site by site. Lets get serious the site is full of hate speech racism, sexism just an all around bad environment. The owner is a straight up psychopath and very full of himself. C++ will solve cancer!

I will start posting chat logs from there just to show the enormous amount of hate mongering going on with this exchange but I think enough folks can vouch for that.

member
Activity: 76
Merit: 10
August 08, 2013, 03:49:39 PM
#10
Before everybody bashes RealSold and mcxNow, you might want to a) get some proof and b) give RS himself a chance to explain things rather than posting publicly.

Also remember that 2FA is coming soon (though not on Aug 10th AFAIK).  Can I remind you that BTC-e only introduced 2FA fairly recently!!

Lastly, usahero, I know you're having some beef with RealSolid and mcxNow at the moment, but raising this post was really low of you.

 - PTT

I will start posting chat logs from there just to show the enormous amount of hate mongering going on with this exchange but I think enough folks can vouch for that.

"Welcome to the Internet!"    Cool
full member
Activity: 244
Merit: 101
August 08, 2013, 02:41:59 PM
#9
and ur little dog too
full member
Activity: 244
Merit: 101
August 08, 2013, 02:40:50 PM
#8
SOUNDS LIKE A BUTT HURT OH NO I WAS BANNED THREAD TO ME!!!

FUCK OFF HERO!!!  GET OVER IT!!!
member
Activity: 60
Merit: 10
August 08, 2013, 02:29:18 PM
#7
Before everybody bashes RealSold and mcxNow, you might want to a) get some proof and b) give RS himself a chance to explain things rather than posting publicly.

Also remember that 2FA is coming soon (though not on Aug 10th AFAIK).  Can I remind you that BTC-e only introduced 2FA fairly recently!!

Lastly, usahero, I know you're having some beef with RealSolid and mcxNow at the moment, but raising this post was really low of you.

 - PTT

The proof is ask RS for your password and he can give it to you been that way for a while so that is proof. Even if he changes it he has a great record of usernames and passwords to skim from pools and exchanges for the folks not smart enough to change their passwords site by site. Lets get serious the site is full of hate speech racism, sexism just an all around bad environment. The owner is a straight up psychopath and very full of himself. C++ will solve cancer!

I will start posting chat logs from there just to show the enormous amount of hate mongering going on with this exchange but I think enough folks can vouch for that.
hero member
Activity: 820
Merit: 1000
August 08, 2013, 02:04:27 PM
#6
Before everybody bashes RealSold and mcxNow, you might want to a) get some proof and b) give RS himself a chance to explain things rather than posting publicly.

Also remember that 2FA is coming soon (though not on Aug 10th AFAIK).  Can I remind you that BTC-e only introduced 2FA fairly recently!!

Lastly, usahero, I know you're having some beef with RealSolid and mcxNow at the moment, but raising this post was really low of you.

 - PTT
full member
Activity: 182
Merit: 100
August 08, 2013, 01:49:34 PM
#5
Just wanted to share, that having plain-text-stored passwords isn't the only problematic practice of never-wrong-operator of mcxnow.

That's my main problem there Smiley
full member
Activity: 132
Merit: 100
August 08, 2013, 01:45:34 PM
#4
Password are not stored in plain text.
They are encrypted, and the operator can decrypt them if someone lose their password. They have to answer some security question, like amount on the account etc...

The 2 factor-aut will be implemented in the update after the 10-Aug update.

No developer should EVER be able to read user passwords. This is rule #1 of building a user login system. You generate a random salt for each user, hash their password including the salt, store the salt and hashed password, and only compare hashed strings when they login.

This is now the second time I've heard of this policy and it makes me happy I stopped trading at that exchange a long time ago.
sr. member
Activity: 434
Merit: 250
August 08, 2013, 10:28:20 AM
#3
Password are not stored in plain text.


Possibly. But the admin can read your password. Operator can read any password. The hacker will also be able to read all passwords, if that will be his goal.

Operator could also read your password and steal your funds while blaming end user for having compromised computer. He wouln't get away with stealing all the coins from all users, but he could possibly get away from stealing some users.

Anyway, from the exchanges I noted, only mcxnow does not know any 2FA. Tick tock..?






sr. member
Activity: 392
Merit: 250
August 08, 2013, 10:10:42 AM
#2
Password are not stored in plain text.
They are encrypted, and the operator can decrypt them if someone lose their password. They have to answer some security question, like amount on the account etc...

The 2 factor-aut will be implemented in the update after the 10-Aug update.
sr. member
Activity: 434
Merit: 250
August 08, 2013, 10:03:16 AM
#1
Notice:

Everything mentioned here was fixed by RealSolid in version mcxnow v2 with implemented google authenticator 2fa and encrypted passwords.

Thus McxNOW is now the fastest and the best exchange in crypto world. Congratulations RealSolid on excellent work. Apologies to give you hard time during working on the update. Hopefully some of my ideas were helpful.

-------------------

Just wanted to share my opinion, that text-recoverable isn't the only questionable practice of mcxnow.

The biggest problem I see is that there is no 2FA of any kind.

If you want to withdraw your balance on:
Crypto-trade, you need to know your password and your pin.
Coins-e, you need to know your password and your email password.
Cryptsy, you need to know your password, your email password and if you have 2FA enabled, you need access to your 2FA device.
Vircurex, you need to know your password, and if you have 2FA enabled, you need access to your 2FA device.


On mcxnow, the only requirement for withdrawing coins is knowing account password. Considering that the number of hacker compromised computers is significant, this 1-password-safety policy is very unsafe.

Every other site beats the mcxnow in that regards.


Best regards.


PS: If you will try to dirty my name, I suggest you to deposit all your funds to mcxnow!

ps: this post was edited on 18/8/2013 to remove "plain-text" with "text-recoverable", and topic was edited.

ps2: added notice to original post. 9/26/2013 .
Pages:
Jump to: