Post
Topic
Board Bitcoin Discussion
Re: Im just been attacked and robbed on my MT Gox account
by
CCCMikey
on 06/08/2011, 05:05:20 UTC
Yubikey has been around since about 2008 - I remember when Steve Gibson met Stina Ehrensvrd at the RSA Security Conference, trying to drum up interest in the product. http://www.grc.com/sn/sn-143.txt Since Yubikey is used in many environments besides MtGox, I doubt this entire post exists just to drum up support for it. But then, this is the Internet, so who knows Smiley (It looks a bit to me like someone used a web language translation tool.)

Certainly, if it's true that MtGox passwords can be reset simply by controlling the email address, then that is probably a cause for concern. Up until fairly recently, pretty much all email clients default to POP or IMAP access using plaintext password transmission. As a result, any other non-isolated members of a wireless network have a strong chance of being able to see that password. (Wired networks are generally less susceptible.) All routers between the end user and their email server can also see that password.

Similarly, almost all email clients store the password within the machine somewhere. On Windows, there are plenty of freeware programs that will read the email password in the blink of an eye (mailpv for example) so it too is another security risk. Even third party programs such as Thunderbird will happily reveal your password.

Basically, for financial sites; a simple password reset facility via email is not sufficient security. It needs to be paired with another out-of-bound medium such as SMS, Yubikey, etc.