WARNING - 2 factor verification and its dangers - VERY IMPORTANT - #steempunks #minnowschool

in #warning7 years ago (edited)

I want to share a warning to everyone that is using 2 factor verification for exchanges, finance and permanent accounts.

A friend of mine has recently invested in some KCS from the kucoin exchange with the intent to invest. Exchange websites flaunt their 2 factor verification feature and people assume its more secure when you have it so they go for it.

(Image not shown due to low ratings)

(Image not shown due to low ratings)

(Image not shown due to low ratings)



(Image not shown due to low ratings)



Images were hidden due to low ratings.
Sort:  

Never thought about it, OF COURSE.
I guess it is tied to the phone number, which is the SIM. So maybe this would give ample motive to actually purchase an old phone bone from 2004. They simply work like they should, the battery lasts forever and you can leave it in the sunlight and it will still function.

Having had terrible experiences with a smart phone a friend gifted me I am never going back to these sensitive and fragile pieces of "high technology". Especially now.
Thanks for the heads up!

 7 years ago  Reveal Comment

I have no reason to doubt what you're saying, I'm afraid I just don't get it yet.

Does that apply to old phones? You know, Samsung ones with built in spelling mistakes in their auto correct. Long before operating systems. I wouldn't even know how to reset that phone "software" - there's no real port or OS. And the number the verification arrives at is on my SIM, I can put the card in other phones and it will have the same number.

Isn't it true that as long as I have the same number on that old phone it will still work after resetting? How would the exchange know that anything is different? How would the phone not tie to its SIM number after rest? Because "modern" phones work differently and require OS shenanigans to access the actual number?

You don't actually need to answer these, just thinking out loud here, pondering how to best protect the access. I have had some hardcore password lessons in the last years that taught me a lot.

I know a few people who religiously reject smartphones <3

 7 years ago  Reveal Comment

Use authy for your authenticator app if u are worried about this as you can move your 2fa accounts across devices with it

Great info man, thanks for sharing. I have resteemed so my 20 followers can be made aware!!

This post has received a 0.35 % upvote from @drotto thanks to: @banjo.

Your Post Has Been Featured on @Resteemable!
Feature any Steemit post using resteemit.com!
How It Works:
1. Take Any Steemit URL
2. Erase https://
3. Type re
Get Featured Instantly � Featured Posts are voted every 2.4hrs
Join the Curation Team Here | Vote Resteemable for Witness

wow, thanks for the heads up. I'll recheck all my 2fa verification and disable the important ones.

I've had some accounts that I had to send extra documents to gain access to after having a phone stop working, so I definitely know where you're coming from here!

The Daily Sneak.Thanks to @paradigmprospect, this post was resteemed and highlighted in today's edition of

Thank you for your efforts to create quality content!

Useful points made on this post.

Worth knowing though that in some accounts you can save yourself a lot of heartache if you save the seed or code they show you when you first set up the 2FA as this is an easier way to set up 2FA on another phone. I personally have an encrypted unasuming usb fob and a note book and write all important information on both. I keep them in separate places and if in the guture things become an issue or my machine/phone/laptop dies I have a backup...

Always store these sort of information off your computer on either an analogue or a encrypted device OFF the computer.