pwned!I received several negative trust. Okay.
I was able to get access to SPQRCoin yesterday answering "1+1" with "2". No joke. He is in DefaultTrust level 2.
greenplastic gave negative trust to me. Now he is security locked for using "5" as answer to "how old was justin in 1980?". He was warned and had left this stupid question (answer should be between 0 and 99, the rate limit is one try per 45 second and IP address - in reality, you get a bunch of IPs and laugh about the limit).Proof:
https://bitcointalk.org/seclog.phpFor the record:
- Today at 06:39:10 PM - greenplastic - password reset via secret question
My hat is a little bit grey, so I probably would have switched the stupid negative feedback against myself to positive before locking the account. lulz.
His negative feedback against you is still there. Yes, I think that you are probably not malicious. You are definitely a little bit naïve.
Security questions are a joke and should be disabled. There are members using questions with a probably secure question or maybe even fake questions, but "1+1" is a joke. In case of greenplastic, he did not even understand the problem. We should think of who is member of DefaultTrust.
Security lock is a good thing for sure, otherwise I would control two DefaultTrust accounts now, one of them being inactive for months. Thank god, I was not able unlocking using a fake mail. I want to see security questions disabled, option to disable email recovery per account and 2FA introduced. BCT is about large sums and does not have up-to-date security mechanisms.
I gave
only 5 merits for this, because I am widely merit-boycotted; I need to save up, so I can afford to give more when you make a thread about this.
I want
public key authentication. Disable password authentication (like in
sshd). Has the
Bitcoin Forum ever heard of such a thing as
digital signatures? Do people here do
crypto, or not? Sigh.
I made some suggestions years ago. Nothing happened. Your way is better: Teach a little lesson, which will be less painful coming from you than from someone who actually wants to pwn a bunch of accounts. It will more likely result in positive changes.
Check the username. Does it remind you the user alia?
Get a grip. No other way to say this: That is ridiculously stupid.
Yes, I may be stupid but how are you so sure 🤣
Because I knew alia
as I wish for people not to be reminded—ugh. A smooth-talking gambling addict sex scammer, likely from India or SEA (IIRC), who only temporarily fooled people with a pretense of some technical skills. Not a German hacker who just kindly refrained from helping himself to some tasty DT accounts. To make a connection based only on a very vague similarity of names verges on how schizophrenics find secret messages in white noise.