Post
Topic
Board Meta
Re: [Controversial] Who's to blame when an account gets hacked?
by
moonpie45
on 08/01/2017, 20:39:18 UTC
The best thing that can be done is that, a PGP key should be made mandatory for signing up on this forum. This does a lot of good.

1. It prevents account farming because I believe making a huge amount of PGP keys is definitely tough.
2. It increases security. As a person who is genuine usually holds only one key and hosts it on a public server.
3. On creating an account, the person should be staking his PGP Public Key on a thread and he would have to use only that PGP keys while he trades via that account.
4. Also, in a case an account gets hacked, a simple message from the account linked PGP key should be signed to verify the authenticity of the claim.


This would definitely make this forum a better place, but this is according to my knowledge. Maybe more knowledgeable people here might have something more substantial to say.
1 - in the time it took me to read your post, I could have generated many PGP keys.

2 - If I wanted to, I could store many PGP keys on my computer (and backups). I do not host my PGP key on any keyserver, I upload it to one keyserver and it will propagate to other keyservers over time.

3 - Just like bitcoin private keys, PGP private keys have the potential to get compromised, or lost. If a PGP key is compromised then the owner should revoke the key publicly, and will probably want to start using a new key.

4 - Just because someone signs a message that their account was hacked does not make it a true statement. All that a PGP signed message will mean is that the owner of the PGP key is making the statement. It would be possible to fake getting hacked if a lender fails to ask for/verify a signed message.