Poloniex's 2FA is now broken, I can log in to other sites with Google Authenticator -- but not Poloniex!

in #bitcoin7 years ago (edited)

UPDATE 2018-02-17 Sat: GOOD NEWS: I got back in. I had changed my phone's clock recently to "network time" as sometimes texts would arrive "before" the one I had sent that they were in reply to. Turns out that broke Google Authenticator. If you happen to do this, here's the fix: tap the "..." (menu) icon, go to Settings, which has two choices: "About" which opens a tab in your browser to describe the feature, and "Time correction for codes" which will reset the internal clock of the Authenticator app, which worked perfectly.

Odd, though, that WEX worked every time. And still does!

EDIT/UPDATE 2018-02-16 Fri: apparently Binance is affected as well. I was able to log in to WEX just now, so it's not "all Google Authenticator sites are closed to me", only 2/3 of my exchanges... :(

 

Whole story is in the title. I've opened a ticket, for them to ignore like all the others.

Be careful out there!

May your trading be profitable -- financially, spiritually, and emotionally.




Sort:  

Should have withdrawn my coins out of exchanges .

Agreed. I noticed this while migrating tabs from Firefox (it's way too slow on this $4k laptop! -- so, it loses out to the spying Chrome) -- the Poloniex tab auto-logs itself out whenever I switch the VPN, so I had to log into that one not only after copying, but also in the Firefox tab once I realized I couldn't get in; neither worked.

I did WEX first, and that logged in, so I didn't think I'd have issues. When I had the first with Poloniex, I reported it. I was more careful while doing Binance -- it is okay with the IP address of my laptop changing, so it was still logged in. Couldn't log in via Chrome, but it's still logged in on Firefox.

So I can get my coins out (of Binance, that is), which I'm about to do. And, learn about decentralized exchanges!

Owh man, had been researching about them and thought i'll make a steem post about decentralised exchanges once i figure it out. Feels like i better let the experts handle this,I'll do my due diligence and post any info on my experience of decen exchanges. Phew! Things move sooo fast in this space,crypto is no-chill!!

Is Myetherwallet safe for storing ?

Hahahaha. Really, how can I do this sir.

Hahaha, really educative, hilarious and also sounds religious.

Thanks for sharing @libertyteeth.

I’ll be visiting your blog for your awesome posts, thanks to steemauto.com that helps me in up voting your posts at anytime you submit your posts, thanks also to steemd.com that brings the history alive so that I can comment on your blog posts.

www.steemauto.com

Its a site that automatically upvotes anyone that you’ve counted his/her post trustworthy and have set the steemauto to upvote once the person posts, (your fans and friends)

Will you be signing up, the service costs 0.001sbd

after setting it up, use ‘Fanbase’ menu there to add your fans, I’ve added you already.

I think @gentlebot has been brainwashed by the span bots.

Thanks for the warning sir. I will publish to benefit everyone
#resstem

i think no time to convert on decentrelized exchanges and take your all from these centrelized exchanges if we want to save our money and cryptos @libertyteeth
because now we cannot trust on centrelized exchanges security

Yes i have the same issue i'm gonna read their twitter to see any update or some news about this problem. Regards

Try to erase your cache now i can log in some times you just need clean cookies and cache :)

Tried it, Binance and Poloniex still failing. Logged out and back in to WEX, worked with no issues.

Also, note that Binance changed their 2FA handler recently, "making it easier for you" by removing the need to hit Enter -- which means, if you typed the last character wrong, you get to wait a whole extra minute rather than being able to hit backspace and hit the right one, then Enter.

I find this a step backwards. Also, sometimes my 2FA doesn't work right when it's "near" a minute boundary; so, I have been "timing" my hitting Enter while watching the 2FA count down on my phone. With Binance, now I have to wait to hit the last digit. Annoying. Like the new stupid chip cards, which require you to leave it in the machine longer than the stripe, and also, the noise it makes on "success" sounds like an error!!! Awesome step forward, banking overlords!

I understand @libertyteeth but i think in your case is a particular issue that you have, i mean is not a general problem and this cases you have to find a particular solution but thinking about the support of poloniex you'll have to wait a looong time so they have and awful service, friend try to use decentralized exchanges when you solve this problem, they work great. Regards

Well, I created a BitShares account a few months ago but didn't see many options for purchases there. What do you use for decentralized exchange? Thanks!

Yes it's totally true, the problem with decentralized exchanges is the low volume and the low quatity of coins, i use waves mostly and i really like it but people don't use it and i don't know why. Regards

Thanks! I'll keep an eye on it. Decentralized is the way to go -- once everybody goes there! :D

Well, you are both very proficient in this field ...
I find many difficulties here. I will learn more about this.
If you delete cookies, it's usually safer with ccleaner

I fucking loathe those goddamn chip cards! Thankfully my bitpay card is still swipe only.

Thanks for the information @libertyteeth ...will share it too

Amen sir.

Let me see their page if there is any info about it also. This is bad @libertyteeth

Crypto exchange issues are such a nuisance its important to keep the community informed. Thanks!

ohhh thats bad whats this mean , will polo be a scamy or hack like two others like italy and japnse exchanges @libertyteeth?

ohh you edit updates whats your suggestion or think to remove 2fa
any problem in 2fa security or some other issues site

Well, I can't remove 2FA if I can't login! But, that's an idea -- I could remove it for Binance, since I haven't closed that tab in Firefox yet (was migrating from Firefox to Chrome when I discovered this issue).

I would personally start thinking about getting most of my coins out of the exchanges, I'm terrified about what a suden death of Tether might do :s
Did you manage to get in by now?

Yes, had a revelation about a change I made recently which WAS the root cause of my being locked out -- updated this post with that at the top. I had changed my phone to "network time" because it was showing people's texts who replied to my earlier texts, above them since the time had drifted. Related to this is that the Auth app would sometimes fail, and it seemed to be when it was at the very beginning of a minute, which drifted over time to me needing to type the digits right as the timer was ending -- and then, a second after the timer ended. So I should have put two and two together, earlier, but at least I wasn't locked out of any trades that I intended. Oh, just to be thorough -- the fix was in Settings in the Auth app, then "Time correction for codes" and all three exchanges now work. I was a little concerned that WEX wouldn't work, so even though I had logged into it on Chrome, I kept that logged in and loaded a Firefox tab, and tried logging in and it worked.

So, WEX must be a little bit more forgiving than the other exchanges. I wonder if that's, like, a server-side setting for Google Authenticator?

Nice action in Verge and Tron today! Been hodling those for over a month now, great to see! Still underwater but coming up for air! :)

I'd like to belive that you are on proffit with XVG by now.
and damm, I had the same issue with the clock, although i don't use the phoen authenticator but the aap Authy anyhow i trust more the security of chrome than my phone.

Nope; bought SVG at 963 and TRX at 700. Glad to see them rising again!

Interesting to hear similar clock issues, thanks for sharing!

I'm just trying to get my steem out of there its been like 3 weeks place freakin sucks!

Which? I know Poloniex has had "wallet issues" forever -- but Binance just added STEEM so you might be talking about them. I haven't much "traded" STEEM as it takes 13 weeks to get it all out, so it's kind of an enforced hodl...

@libertyteeth That's why i'm not using Google Authenticator .. even if my account will be secured , it's safe to keep your coins in your wallet instead of exchanges , Thank you so much for warning (y)

so i noticed it some time that it maybe some mistake in your browser or some time face issue in your ip so try next time and hope it will solve ,,but if it is really issue then sure the fear around these exchange is strong and we care our money as you say

You were spot on with the "time face issue" -- that's what it was. Updated the post -- scroll to the top for full details. Thanks!

i think you are sir,,,great job and analysis

this is scary to me as if it happens with me i will be going all bonkers all over

Yeah! First I freaked out and wanted to start smashing stuff, then I took a few deep breaths and decided to call out for help. After a night's rest, my brain said "hey maybe you did this to yourself, explore the Auth app" and I fixed it and updated the post above.

It was scary though because WEX worked, and Binance and Poloniex didn't. That was and still is concerning; are there "more forgiving" server-side settings, or something, when a site integrates with Google Authenticator? Most likely, based on this experience.

ohhh thanx sir for this udpate i didnot check my polo account from last 4 days but i think we transfer our cryptos in to wallets or go in decentrelized exchanges but there is a problem they provide only some cryptos in decentrelized exchanges not more @libertyteeth sir
so whats your opinion in this situation?

It matches yours, and @dim753's comment on this page as well. Low volume, low quality of coins, small selection. As I said to him, decentralized is the way to go -- once everybody goes there! :)

I was able to log in just fine @libertyteeth.

20180217_070827.png

I panicked just seeing your post so I had to check

Yeah, seems I caused it myself. :( But, I figured out what I had done and edited the post, so in case anybody else experiences this, hopefully they will be able to resolve it faster than I did. Onwards and upwards! :)

Yes! Onwards and upwards! Keep uus updated on these kind of stuff.

I had 2fa on my Gmail and poloniex both, I don't know how he did compromise my poloniex but he did, what should I do for it?? Hoping your early response.
Thanks for info...upvote n resteem

I would contact Poloniex support. And, not hold my breath...

Ticket #755397 . Thanks for advance !
@libertyteeth

Sure thing! The "not hold my breath" was regarding their lag times -- I have tickets in there which haven't had a response ever; some which they started responding to, but haven't had one in months, etc. In their defense they are opening lots of new accounts with "dust" in them so it's expensive for them to take the smaller customers, especially when they don't know what they're doing so they have to spend support salaries on it. Note, not saying that's your case, just that they needed to hire a lot of support staff to handle the increased volume.

Hope your ticket gets attention!

Pray for me brother...

great upgrade news,,thanks for sharing

In the middle of upvoting people, my Steemit account logged out. Bugs everywhere!

I made sure it looked to me like "https://steemit.com" at the beginning of the URL. Still, it's unexpected behavior like this that makes one think "perhaps they're about to steal all my shit."

Ooops bugs is really causing a drama. Using this opportunity to tell you thank you for the auto upvote you placed my account all those times. I am forever greatful and i return i have long ago placed your account on my auto upvote for life even when i become a whale in this platform time to come. You should me love when nobody did. Manage my cent for the now @libertyteeth

That's awesome to hear, thank you @tfame3865!

I'm conflicted about this upcoming contest; I'm in a lot of pain, still, and someone pointed out that there are bot armies gaming my contest. Wonderful... :(

There's a lot of names up there now. It's your contest though, change how you choose, or just say 'This contest cancelled due to scum bots.' or something.

I've started processing the data. It's gonna take a while... But it's in progress.

Amazing the information. Good posting @libertyteeth...
Thank you very much...

that's right,i am also agree with you sir...

Shocking, i already shift my crypto over to bittrex because polo is too dangerous to use now, thanks for sharing this information with us friend, Stay blessed

One thing to make sure is that your device's clock is set accurately, being out of sync will result in invalid 2FA codes.

Also perhaps take a second look at what you wrote down, see if there are any potential typos, try some variations?

What you said man,It's a really?
Oh! man thanks for share important news.

Coins are not indeed safe in any exchanges ,that is to say !

Which decentralized exchanges are good ?

After reading first part I was of opinion that let me check my account after seeing my account working I thought yaa let me tell you that there might be some small issues but after reading full post I was just so happy for you because it requires lot of effort to build a portfolio and if you loose that then you even loose your money....