Post
Topic
Board Beginners & Help
Re: How I almost lost my account.
by
Saint-loup
on 06/06/2024, 21:37:50 UTC
Besides that, you could have set a secret question first, you wouldn't need to remember your throwaway address.
Quote
Secret Question:
To help retrieve your password, enter a question here with an answer that only you know. Using this feature is not recommended. Anyone who guesses your secret answer will have access to your account. It's like a second password.
Answer:
Choose carefully, you wouldn't want someone guessing your answer!
https://bitcointalk.org/index.php?action=profile;sa=account
Secret question will trigger an account lock for security reason, it does not help you to recover your account or password.

This feature was disabled after a forum hack (sever compromise) in 2015.
On May 22 at 00:56 UTC, an attacker gained root access to the forum's server. He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server. In the intervening time, it seems that he was able to collect some or all of the "members" table. You should assume that the following information about your account was leaked:
- Email address
- Password hash (see below)
- Last-used IP address and registration IP address
- Secret question and a basic (not brute-force-resistant) hash of your secret answer
- Various settings

PSA: ACCOUNTS WILL BE LOCKED IF THE SECRET QUESTION IS USED TO RECOVER IT
You are kidding  me dude? You are talking about an event that happened almost ten years ago and quoting posts from the same period. I hope everything is back to normal ten years later. If one user has created his account after the 2015 hack, how hackers could have taken his secret question? It's not possible.