Post
Topic
Board Meta
Re: what is my mistake?
by
mprep
on 12/03/2018, 22:44:38 UTC
Typically, the only acceptable method of proving ownership is by signing a message (including current date and desired new email address) using a Bitcoin address or PGP key associated with the account.

While other global moderators might accept a message signed with an ETH address as proof, I'm not going to until I get an explicit acknowledgement from theymos. Technically, all account recovery should be done by admins but since simple security locks don't require an email changed, any global mod can do it. As for whether they're accepted by the admins as proof for a recovery of a hacked account, that's something you're going to have to ask them.

AFAIK both signing and verifying messages is as easy as for Bitcoin addresses. As for security, it's probably on par with Bitcoin though I haven't really dived into Ethereum's technical side to be 100% sure.

That post from theymos was from before Ethereum existed, so given that the security is (probably) on par with bitcoin's message signing and private keys then I would imagine theymos wouldn't have a problem with this. I was looking for more of an explicit statement that excluded Ethereum addresses being used in this manner. I've read that post many times, and while I do see your point about it not being explicitly stated that anything other than Bitcoin addresses can be signed, I hope you will reconsider or at least query theymos about this issue for the sake of clarity if nothing else. There is no other information regarding this? It seems strange that some staff would operate one way and some of you would operate another on a matter of account recovery policy. That seems a rather important issue to be uniform/consistent on.

Have you attempted to ask theymos about this yet?
Nothing's stopping theymos from updating the thread to include ETH, LTC or whichever altcoin he wants. In fact, the thread was last edited on October 25th, 2017 (hover over the post's date) which means he has nothing against updating it when procedures change. As for asking him, since this technically isn't even my responsibility and I'm still waiting on an unrelated request I've PMed him about a couple of days ago, I'll leave it to the user in question to convince theymos to add additional account recovery methods.

The reason certain global mods handle account recovery differently is because we're doing so unofficially (there isn't any forum policy requiring us to handle such requests nor is there anything prohibiting us from doing so) and only for a small subset of these requests (non hacked locked out accounts).