Page 1 of 1

E-mail Confirmation For Payout Address change

Posted: Sun Aug 09, 2015 4:23 pm
by tucsondirect
(E-mail Confirmation For Payout Address change) I know this one has a lot of leg work, but it would be a great increase in security, if payout address changes must be confirmed via e-mail.(not Percentages)

Also failed login attempts in excess of 5 failures from an ip range not previously authenticated, should cause an account lockout. :idea: (or just 5 failed login attempts)

Edited for clarification

Re: E-mail Confirmation For Payout Address change

Posted: Sun Aug 16, 2015 11:25 pm
by twitzay
My first read! I'm new to mining, but not exchanges. Where's a good starting place? And yeah, 5 failed logiin is an issue perhaps.

Re: E-mail Confirmation For Payout Address change

Posted: Mon Aug 17, 2015 9:05 am
by Steve Sokolowski
The E-Mail confirmation is a difficult issue that I hope tuscondirect will address.

The problem is that we don't take E-Mails now because customers are often concerned about privacy. If we start associating E-Mails with accounts, that brings up privacy concerns.

Do you believe the need for a feature like this outweighs the privacy concerns?

Re: E-mail Confirmation For Payout Address change

Posted: Mon Aug 17, 2015 1:40 pm
by tucsondirect
Maybe instead of e-mail address, user would be required to input one of their payout addresses(if assigned), and make a change so the dashboard only shows the first and last 6 Characters of an existing payout addresses (or implement a PIN system... but that could be a problem for forgetful users.... they should always know/ be able to find their payout address ;) )

Edited to add, policy should be put in place to only manually unlock an account if the user submits a message signed by their wallet address requesting that prohashing.com removes the lockout from their account, and that the signed message comes from an address that was associated with their account BEFORE the lockout occurred

Re: E-mail Confirmation For Payout Address change

Posted: Mon Aug 17, 2015 2:14 pm
by tucsondirect
For wallet address changes.... thats a more unique problem because the transaction id's would expose their address thus making it compulsory to provide it before changing it to a new address is pointless :/ perhaps the option to use 2FA (authy/google/etc/