I think the Altswap/Firemine listings looks strange. For example the fact that they reused the webpage for those listings and how they haven't been very clear about what they actually mine with or what they buy for the investors money and some other things in how the contract was formulated, also the price they seems to have payed per GH and what each GH seems to be generating don't seem to make much sence, but with that beeing said:
....
If someone has access to your email, despite you having 2fA set-up, they can click lost password, and then a new password link will be sent, when you click that link and make a new password, it logs you in and overrides or disables your 2FA!!!!
....
and cashed out about 1 bitcoin
....
If this is what happened it's a bad flaw in CS system that they should fix as soon as possible, the whole point with 2FA is to make it impossible for someone that may get access to an email/password from doing any harm, even CS should realize that and maby they should compensate the issuer at least partially for that and if the losses "only" were 1 btc there shouldn't be any problems for Cryptostocks to take that cost as they charge each company 1 btc to list at there site. But it's stll up to everyone to protect there emailadress so even if the 2FA don't work the way one can expect it to do it's not fully CS's fault.
I emailed cryptostocks for 2 days trying to get a response about this.... first email I got was the following:
Cryptostocks support is known to take long time in most cases, some exceptions exists thou when they acted and fixed things within minutes/hours.
Finally the addressed my concern by saying this....
Dear user, assuming that you have protected your email account (e.g. with 2FA) then this is not a flaw, you can only reset the password if you have access to the email account.
How Kumala is thinking here i can't see, he clearly haven't realized what the 2FA used on CS is for then and some email accounts dont even have the possibility to protect the email with 2FA. Kumala if someone have 2FA on at CS, then no one should be able to reset there password without access to both the email and the 2nd authentication used, they should not be able to log in, not be able to buy or sell anything and not be able to withdraw anything.
I think i read way back something about that CS was sending out a postcard after a week or two to those that wanted to advanced verification to verify that there address was real as a step in getting that advanced verification. Maby something similar could be done to make sure resets of 2FA or changing of password is done by the correct person, or maby have people register there accounts with 2 emailadresses and both emails would have to confirm a change of password or reset of 2FA there could also be an automatic delaying of the change by a week or two if someone wants to change password or reset 2FA to make things safer.
Edit reading what you said a bit closer
We could not figure out how they gained access but I just tested it and it is, in my opinion a very serious flaw
...
If someone has access to your email, despite you having 2fA set-up, they can click lost password, and then a new password link will be sent, when you click that link and make a new password, it logs you in and overrides or disables your 2FA!!!!
Shouldent you have seen pretty mutch directly that something was wrong, if someone changed your password your old one sholulden't work, how have you been able to log into CS up until recently if CS support diden't answer you for 2 days ?