Post
Topic
Board Meta
Re: Why changing the email and the password is so easy !!!!
by
al1n
on 11/02/2018, 17:18:30 UTC
Forum was created in a period when bitcoin was probably the only coin available. That times are over.
Most of the people nowadays use bitcoin (if they even use it, because there are other alternatives)
only as a meaning to an end: to convert altcoins into fiat. And for that you don't even need a personal wallet,
the one(s) from exchange(s) is(are) more than enough for the purpose. Asking for a signed message with
bitcoin address as the only way to be able to recover an account seems rather archaic and leave a lot of people without a real option.

2FA is the way to go. It doesn't need to be phone connected, there are plenty of other alternatives.
Any TOTP code can be obtained on any computer as long as seed is known; you don't need a phone for that.
Also asking the user for confirmation before doing a critical change to the account should be mandatory.
That means at least sending a mail with a confirmation code. That's minimum security, any site has such an option implemented.