Post
Topic
Board Altcoin Discussion
Re: [NOTICE] mcxNOW had a leaked database run against the login system
by
TheRealSolid
on 16/09/2013, 08:24:12 UTC
One simple thing could have prevented it that many other exchanges have already implemented.

Withdrawals only through email verification

Or 2FA. The problem is these people who use the same user/pass at every site typically don't care about enabling extra security features either.

But why do you unlike other exchanges not require email verification?

Its a major security step the "most secure" exchange should probably have

I believe emails are an invasion of privacy of my users. I've removed them from the site and now will only support offline second authentication methods such as google auth.