Post
Topic
Board Exchanges
Re: SECURITY IMPROVEMENT IDEAS FOR BITFINEX
by
mjr
on 19/11/2014, 18:36:53 UTC
...

* Your e-mail account is ONE factor. ONE. Period.
...
Not correct, Gmail has 2FA if one wants to enable it.
I have it and recommend everyone to have it.

Yes, I have my entire google account set up with 2FA.

But, to be fair, let's say you use a specific phone just for 2FA. So there is a truly separate second factor, they take your main phone which has your email. They can then probably send emails as you, and find out which email you used to open the account (assuming this is a targeted attack), so they might be able to disable 2FA, BUT, if they also said that they needed to reset the password, I think that this would not work, as it is highly suspicious to lose your phone and forget your password. So, I think it is two factor, since they can't access your bitfinex account with ONLY the 2FA disabled.