Hirdetés

Új hozzászólás Aktív témák

  • bobalazs

    nagyúr

    Note that CB uses horrifically persistent session tokens that are capable of authenticating without userid, password, or 2FA. Browser cache security is more critical than you think. If ANY attacker gains access to your browser cache while logged into CB they will have complete control of your account. Allowlisting (#14) will slow them down but it will not stop them. You will need to monitor your account for alerts at least every 24 hours for allowlist modifications. If you doubt the danger of session tokens, simply login to CB, close your browser, change your IP, and relaunch a browser to CB. You'll notice no 2FA is required (long lived session tokens).

    És ez igaz is. Jópár napja léptem be, Március 31. Jelenleg is meg tudtam nyitni a coinbase oldalt, nem kért semmiféle beléptetést.

Új hozzászólás Aktív témák