Warning : MyEtherWallet turn on 2FA is Phishing

in kr-dev •  7 years ago  (edited)

오늘 slack 에서 메시지를 받았는데,

피싱 메시지라서 주의를 부탁드립니다.

이더리움 소지자에게
피싱 공격이 증가하고 ETH 네트웍크의 요청이 증가해서 모든 ETH Wallet 에 2FA 를 적용하기로 결정했다.
MyEtherWallet.com 에 접속해서 지갑을 새로운 보안 레벨로 업그레이드 해라.
새 보안 프로토콜 구현되지 않으면(지갑을 업그레이드 하지 않으면) 모든 펀드에 대한 접근을 할 수 없음을 명심해라
어쩌구저쩌구...

결국 링크는 "myether valet . 컴" 이었습니다. 100% 피싱입니다.

저는 접속을 시도 해 보았습니다만, 메타마스크가 이를 감지 하는군요..

마이이더월릿에서 2FA 를 할 수 있느냐는 질문이 있는데, 이는 가능하지 않다는 것이 답변입니다.

2FA 는 OTP, SMS 등을 이용합니다.
OTP 를 쓴다면 서버에서 OTP 가 정확한지 확인해야 하며,
SMS 를 쓴다면 서버에서 SMS 발신/확인을 해야 합니다.

마이이더월릿은 이러한 서버를 두지 않고 있습니다.

피싱이 극성이네요...
메타마스크가 큰 도움이 되네요....


Today I got a slack from Slackboat @nxtchat.

Be careful : This message is phishing itself.

@amachleb asked me to remind you “To all Ethereum Holders:

Due to the increasing number of phishing attacks and holders requests from the ETH network, we decided to implement Two-factor Authentication on all ETH wallets.

Please visit Myetherwallet.com to upgrade your wallet to the new security level.

Please be aware that you will not be able to access your funds, tokens and wallet anymore if the new security protocol is not implemented.

We are taking this measures to protect both you and our network from phishing and malicious attacks.

Thank you for your cooperation and understanding,

The Ethereum DEV team.

The message is 100% phishing.
I tried to access the url "my ether valet dot com".
However Metamask wallet plugin in my chrome detect malicious URL, and protected me.

Question : Can I turn on 2FA for MyEtherWallet?

https://myetherwallet.groovehq.com/knowledge_base/topics/can-i-turn-on-2fa-for-myetherwallet

The Answer is no. Because 2FA is server related work.

No. And if you landed on a site telling you that you could, they are lying to you and trying to steal your private keys.

2FA / MFA is something that works for server-side applications in order to add an additional layer of security on top of the username / password.

In the case of MyEtherWallet.com, a client-side application, you store your key. That key is the core piece of information that allows access to your account and, while you can encrypt it with a password, there is no server that can verify or track a 2FA login / OTP when you are using MyEtherWallet. If someone gets your private key (keystore file, mnemonic, passwords), they have complete access to your funds. There is no stopping transactions, canceling transactions, or resetting passwords.

Basically, it's an authentication primitive, not a cryptographic one.

In order to implement it, we would need to store your key and protect it on our servers, which is not something we aim to do. If this is functionality that you do want, feel free to use any exchange / hosted wallet like Coinbase, Kraken, Poloniex, Bittrex, Bitfinex, Gemini, and so forth. Just be aware of the risk of letting someone hold your keys for you.

More information: https://github.com/kvhnuke/etherwallet/issues/292

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

메타 마스크를 사용하지 않더라도 저 용도로라도 설치해야겟네요.

와 조심해야겠네요. 남의 돈 먹기에는 사기가 제일 쉽다더니... -_- 좋은 정보 감사드립니다.

Congratulations @kdj! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the number of posts published

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

가상화폐는 특히나 보안에 신경을 써야할꺼같습니다.

100번 강조해도 모자람이 없죠 ㅠ

정보 감사합니다.

Its unfortunate for me that I have already clicked such link and logged into my account with my private key. My question is will it be a problem for me in the future? I still have nothing in my wallet but i might have in future.

NO NO NO!))) You're lucky that the wallet was empty!

Do not use the account (address). Private key is already known by the hacker.
It is good if the wallet has nothing. Forget the address.

Create a new one if you are storing ETH in future.
Keep private key safe. Never let it known outside.