A CALL FOR TWO FACTOR AUTHENTICATION [IMPORTANT]

in #security8 years ago (edited)

ANTI-HACK PROTECTION

With the large number of NEW users signing up for Steemit and the recent Bitfinex Hack, I think it's a good time to discuss the option of adding Two-Factor Authentication to user accounts and how it may help secure accounts and even prevent some unfortunate losses.

Steemit is basically a web wallet which stores your funds. Well designed and easy to use most non-crypto users are unaware the importance of protecting their passwords and more importantly Securing your computer.

Even with Steem's very secure passwords it's quite possible a user's computer or device is compromised and a hacker will be able to gain access to their account. The use of a second form of authorization would prevent and eliminate many of these potential cases.

There are many applications that offer two factor security and I believe the most popular ones are Google Authenticator and Authy

Both these applications provides a unique 6 digit PIN on your cellphone which changes every thirty seconds. This PIN is required when logging in and sending transactions. Having this secondary form of VERIFICATION would foil most attempts to breach/hack users accounts since the attacker would have to obtain a user's password and their physical mobile device to obtain the secondary code needed to access the account.

you know your password & you have your phone

Inevitably as STEEMIT GROWS there will be more users with larger balances in their accounts who will become targets for hackers. This is unfortunate but again this is the reality.

Every day I login to Steemit and I see new changes to the platform. I hope in the coming weeks we see some security features like two factor authentication added this already thriving platform.

note If new user are looking for easy way to remember are store your password since they can be difficult to remember check out @robrigo POST which describes how to set up LastPass

Sort:  

2FA seems like a pretty logical fit here especially as long-time users become vested. 2FA however, wouldn't stop what happened to bitfinex from happening here as it happened at the wallet level of the organization but I see the motivation :) . Good post!
I would also maybe add that when you use 2FA you should always have it on a separate device that doesn't have access to your accounts that utilize 2FA (e.g. no stored passwords in the web browser). Also when you setup your 2FA don't have it send a copy to your email - if your computer is compromised its a good chance your email is too and 2FA becomes a non-factor at that point.

Is two-factor really needed now that we are using random 32 character passwords? I'm ignorant of security, is it possible to crack a chain like that?

It is not only about cracking your key, there are multiple other ways to get your password if your computer gets infected with a virus/trojan for instance or somebody has access to it while you are away and you saved your password for convenience and so on.

I never gave that any thought, thanks.

I'm also in favour of adding 2FA as additional security measure to safeguard your account. As more people and money get poured in Steem security concerns will just continue to increase...

I am totally in support of 2FA....

Nice @satoshifpv
Shot you an Upvote :)

Nice @satoshifpv
Shot you an Upvote :)

Coin Marketplace

STEEM 0.16
TRX 0.15
JST 0.028
BTC 54260.52
ETH 2284.10
USDT 1.00
SBD 2.30