Pages:
Author

Topic: MtGox and 2 Factor Authentication - page 2. (Read 2312 times)

legendary
Activity: 1078
Merit: 1000
Charlie 'Van Bitcoin' Shrem
July 13, 2012, 04:47:22 PM
#3
Given that people are extremely lazy about account security I propose that mtgox requires mandatory 2 factor authentication for all accounts.

Also, stop withdrawing coins and dollars immediately! There should be a 24 hours notice for withdrawal. This give the chance for users to review and stop an action if they deem suspicious. (For users who crys for immediate gratification, force them to use 2 method for 2factor authentication at once, charge them a high fee for added risks, etc)

Also, 40K bitcoin withdrawal limit is incredibly dumb. It doesn't match up with 40K USD for a long time now.


If my security suggestions are dumb, feel free to say why. I am not a security expert but I am very interested in NOT REPEATING the bitcoinica fiasco or the mtgox fiasco or any other fiasco ever again.

Kiba, while you are correct that EVERYONE should use 2 factor...this is not why Bitcoinica was hacked.

Bitcoinica was hacked (this time) because they had their mtgox API key on the server which the hacker was able to exploit.

I'm not sure if its possible to do 2 factor with the API.
legendary
Activity: 1050
Merit: 1002
July 13, 2012, 04:45:17 PM
#2
If I'm not mistaken Mt.Gox lets users apply two factor authentication if they want it.

I don't like the idea of mandating actions (it seems a bit opposite of Bitcoin free market theme), but I do like the idea of delayed withdrawals. That would be good if users could choose the option.

Of course, Mt. Gox, or anybody else, is free to apply whatever procedures they wish. I think a recommended security setting notice and warning would be good too.
legendary
Activity: 980
Merit: 1014
July 13, 2012, 04:34:07 PM
#1
Given that people are extremely lazy about account security I propose that mtgox requires mandatory 2 factor authentication for all accounts.

Also, stop withdrawing coins and dollars immediately! There should be a 24 hours notice for withdrawal. This give the chance for users to review and stop an action if they deem suspicious. (For users who crys for immediate gratification, force them to use 2 method for 2factor authentication at once, charge them a high fee for added risks, etc)

Also, 40K bitcoin withdrawal limit is incredibly dumb. It doesn't match up with 40K USD for a long time now.


If my security suggestions are dumb, feel free to say why. I am not a security expert but I am very interested in NOT REPEATING the bitcoinica fiasco or the mtgox fiasco or any other fiasco ever again.
Pages:
Jump to: