Pages:
Author

Topic: TradeHill - Security Update - 2 factor authentication is live (Read 3261 times)

full member
Activity: 154
Merit: 100
great, just nice to know you're being heard.  Smiley
sr. member
Activity: 420
Merit: 250
We're looking forward to hearing some feedback. Anyone have some experiences they would like to share with us about our 2 factor authentication?
Good? Bad? Like it? Hate it? Easy to use? Confusing? Can't make it work? Let us know.

-Jered

also the duo app code button on my htc wildfire (low rez) was almost invisible it was so far off the bottom of the screen, there was just the tiniest grey line at the bottum of the screen which i figured was the top of a button and i touched it which worked...


the other thing, it seems annoying to have to deal with captcha still even when when you have 2step on ...

I'll forward that feedback to duo sec, they'll appreciate it and knowing them probably act on it quickly if it's possible without changing everything.
We're putting a switch in for the captcha and may just make it default to off if you turn on 2 factor. I'm not a coder and don't want to speak for them before I ask. Maybe that isn't as simple as it seems in my mind.
Thanks for the feedback, it's really appreciated.
-Jered
full member
Activity: 154
Merit: 100
We're looking forward to hearing some feedback. Anyone have some experiences they would like to share with us about our 2 factor authentication?
Good? Bad? Like it? Hate it? Easy to use? Confusing? Can't make it work? Let us know.

-Jered

also the duo app code button on my htc wildfire (low rez) was almost invisible it was so far off the bottom of the screen, there was just the tiniest grey line at the bottum of the screen which i figured was the top of a button and i touched it which worked...


the other thing, it seems annoying to have to deal with captcha still even when when you have 2step on ...
sr. member
Activity: 420
Merit: 250
We're looking forward to hearing some feedback. Anyone have some experiences they would like to share with us about our 2 factor authentication?
Good? Bad? Like it? Hate it? Easy to use? Confusing? Can't make it work? Let us know.

-Jered

It works fine, but it seems Duo Security on my phone can't be associated with more than one service at a time. It completely disassociated my phone from the other service I was testing it with.

I forgot to mention that. I'll go back and edit the post now. Thanks for reminding me. It's limited to one user per device but they've told us that should change before the month is over and they move fast.
-Jered
hero member
Activity: 588
Merit: 500
We're looking forward to hearing some feedback. Anyone have some experiences they would like to share with us about our 2 factor authentication?
Good? Bad? Like it? Hate it? Easy to use? Confusing? Can't make it work? Let us know.

-Jered

It works fine, but it seems Duo Security on my phone can't be associated with more than one service at a time. It completely disassociated my phone from the other service I was testing it with.
sr. member
Activity: 420
Merit: 250
We're looking forward to hearing some feedback. Anyone have some experiences they would like to share with us about our 2 factor authentication?
Good? Bad? Like it? Hate it? Easy to use? Confusing? Can't make it work? Let us know.

-Jered
sr. member
Activity: 420
Merit: 250
Am I the only one who had phone verification turned on without requesting it, and am now locked out of my account?

This is the only one that I've heard of. I'll  look in to it, send an email to [email protected]
Send us your user name and we'll get this taken care of.

-Jered
full member
Activity: 532
Merit: 102
Am I the only one who had phone verification turned on without requesting it, and am now locked out of my account?
sr. member
Activity: 420
Merit: 250
also why the heck do all of a sudden have to be logged in to access this page that i could b4 Huh

this works and loads default USD: https://www.tradehill.com/MarketData/

but any link on that page makes you have to login.... Lame'O

Thanks for pointing that out. It looks like they might have gotten a littler overzealous when they were locking pages down with the Duo Sec.
It should be an easy fix and I let them know. You shouldn't have to log in to look at market data.
Also they have raised (I believe it's in effect) the logout timer which was pretty short.


In regards to the Token, we haven't shipped any so we haven't enabled the feature.
We wanted to get a feel for how much demand there is and buy them in bulk so we can offer the lowest price possible.
When we determine a price we will enable it as a withdraw feature and you can pay directly from your TradeHill balance.

-Jered
full member
Activity: 154
Merit: 100
during TH auth setup a token option didn't appear as an option. i imagine its something you will have to order and pay for at a later date when they become available....
member
Activity: 109
Merit: 10
Physical tokens are not for everyone. As someone who is always on the move and works in industrial environments regularly, it is not feasible for me carry around another usb stick everywhere I go. I would hate to be locked out of my account for a few days simply because I lost the physical token. On the other hand, I am never without my phone, so sms notifications work great for me. I don't see any other exchange providing that kind of service.

Good point, I think the vast majority of people the token is best for but the phone service for customers like you who do need it is a great move.
full member
Activity: 180
Merit: 100
Physical tokens are not for everyone. As someone who is always on the move and works in industrial environments regularly, it is not feasible for me carry around another usb stick everywhere I go. I would hate to be locked out of my account for a few days simply because I lost the physical token. On the other hand, I am never without my phone, so sms notifications work great for me. I don't see any other exchange providing that kind of service.
member
Activity: 109
Merit: 10
omg awesome works amazing

+1

I think this together with the new site currently in production, once released, could see MtGox being left behind very quickly.

Except mtgox sent the same thing to all their customers affected by the breach. And has it available for new users by request, I think.

Not to take anything away from Trade Hill, this is an outstanding business move. Everyone should get one of these (the physical token).

And the market seems to have possibly even reacted to this news. For the longest time it was slightly better to have mtgox usd, even after the hacking, btc prices would be like a few cents lower on mtgox, showing that the market valued mtgox usd more. However, looking at the market for the first time now I see Trade Hill usd is being valued higher than mtgox usd, as 14 Trade Hill usd will get you a bitcoin, as opposed to (the outrageous) 14.1 mtgox usd. I know where I'm trading if I need to sell some btc, at least at the current prices.
full member
Activity: 180
Merit: 100
Works great, thank you. I for one have no problem paying a $1/month to make sure that I am the only person that can log in to my account. People asking you to provide extra security for free that you are having to outsource are being unrealistic in their expectations. With the two-step authentication being optional on an account, anybody who doesn't want to pay a $1/month can simply elect to not use it.  Kudos to you for not trying to make a profit on the two-step fees, when you could have just as easily charged *everyone* a slightly higher commission fee and made a lot more in the long run.
legendary
Activity: 1022
Merit: 1001
omg awesome works amazing

+1

I think this together with the new site currently in production, once released, could see MtGox being left behind very quickly.
hero member
Activity: 793
Merit: 1026
omg awesome works amazing
full member
Activity: 154
Merit: 100
also why the heck do all of a sudden have to be logged in to access this page that i could b4 Huh

i want to be able to access this page and check market data without having to go through 2 factor auth !!

how come USD is open but not AUD

https://www.tradehill.com/MarketData/AUD


edit:

this works and loads default USD: https://www.tradehill.com/MarketData/

but any link on that page makes you have to login.... Lame'O
legendary
Activity: 1834
Merit: 1020
push system works well, just set it up and logged in.

 but note in AU our phone number is generally written as 0435223227 but you must enter it as 435223227

 (this is not my number)

New security works for me too.  Brownie points. 
full member
Activity: 154
Merit: 100
push system works well, just set it up and logged in.

 but note in AU our phone number is generally written as 0435223227 but you must enter it as 435223227

 (this is not my number)
newbie
Activity: 32
Merit: 0
Congrats guys! The more security focused we all are the better off the community will be.
Pages:
Jump to: