Author

Topic: Security Features (Read 153 times)

legendary
Activity: 1878
Merit: 1038
Telegram: https://t.me/eckmar
December 15, 2017, 08:50:38 AM
#3
I understand what you are saying.  A "hack" comes from two ends.  If the site got hacked of course that is one thing.  However; if the hack(s) keep coming on the user's ends there are many things that can fortify your defenses.  I am not asking for an adversary to come after me by any means, but using VM's and only linux has kept me clean as a whistle against these hacks on all sites so far.  Still I have requested that Theymos consider U2F, which is the ultimate protection mechanism and its not too tough to deploy.

I do like the idea of sending a LINK to the registered email account as a REQUIREMENT to change a password or email addy, as long as it would also require that you enter the CURRENT password correctly first.  Password would authorize the link to be sent.  This would protect against someone hacking your email and not knowing your btc login credentials.  Maybe paper code backups if both of those fail.  If you lose all three then tough shit your account is gone ---- grow up time!!

No matter how It happens it can be prevented in most cases but adding simple email authorization. I don't see U2F being added soon because as for now only Chrome supports it and it's kinda complicated and not well documented for developers.
hero member
Activity: 761
Merit: 606
December 14, 2017, 06:49:56 PM
#2
I understand what you are saying.  A "hack" comes from two ends.  If the site got hacked of course that is one thing.  However; if the hack(s) keep coming on the user's ends there are many things that can fortify your defenses.  I am not asking for an adversary to come after me by any means, but using VM's and only linux has kept me clean as a whistle against these hacks on all sites so far.  Still I have requested that Theymos consider U2F, which is the ultimate protection mechanism and its not too tough to deploy.

I do like the idea of sending a LINK to the registered email account as a REQUIREMENT to change a password or email addy, as long as it would also require that you enter the CURRENT password correctly first.  Password would authorize the link to be sent.  This would protect against someone hacking your email and not knowing your btc login credentials.  Maybe paper code backups if both of those fail.  If you lose all three then tough shit your account is gone ---- grow up time!!
legendary
Activity: 1878
Merit: 1038
Telegram: https://t.me/eckmar
December 14, 2017, 02:01:58 PM
#1
Recently my account has been compromised and I know how painful and process of recovery is. My suggestion is adding some security features to the current board (I know new one is in progress but it will be years before it is finished). What I mean exactly is this:

  • 2FA - Might be hard to implement on old platform like SMF and it would take some time to test it since it would greatly impact signing in process
  • Email Approval - Simple and easy solution that would greatly reduced the number of hacked/stolen accounts. Most of the accounts that are stolen are just password changes, and the attacker does not have access to the owner's email address. A solution would be to simply send an email "click here if you want to change your password/email". This solution would require 20 minutes of coding from Theymos (maximum) and it would help admins with the account recovery load long term
 

Let me know what you guys think about this features that I think are needed.
Jump to: