Five Online Security Controls on Remitano and Their Importance

Discussion • 2021/01/06 • by
holyfield898

Cover Photo Credit: BitDefender Post

As Remitano user, visiblemoney, pointed out in his post, security is a really big issue in the cryptocurrency domain. In June 19, over $30 million in tokens were stolen during the infamous Bithumb hack, and as this Remitano post highlights, there are several scams that have really shook the crypto world, including the unfortunate Twitter hack of July 2020 which netted over $180,000. However, this article does not focus on security of Cryptocurrency Exchanges' infrastructure security, but on some simple security measures Remitano has put in place for the safety of its users. The aim is to help you understand and, therefore, appreciate why some features work the way they do on Remitano.

So here are Five Security Controls on Remitano Platform and Their Importance:

Email Login

image

You may have wondered why you don't get to enter your username and password as a user. Remitano uses emails to login users; a link is sent to your email which when clicked logs you in. You can also directly sign in using Google or Facebook. This method has some implications: username and password combination login are sometimes less secure depending on the security controls placed by the webmasters and the users themselves. By webmasters implementation, I mean things like not storing plain text passwords of users, enforcing stronger passwords, etc. By users' implementation, I mean things like using strong passwords consisting of upper and lowercase letters with a combination of numbers and special characters, not using the same password they've used for another website or service, not using self-identifying factors such as birthdays when creating passwords, etc. A common attack known as brute-force attack tries different username/password combinations to see if there is any user on the website who uses such, they find victims of this in most cases. Moreover, if the database of a website a user had registered in was breached, attackers often use the credentials gotten to attempt logging in to other websites, hoping that the user had used the same username and password combination across both sites (which is a very common practice among most online users). As you can see, username and password combinations often lead to some level of limitation about account security. But by using an email login, these limitations are greatly reduced; that your account was compromised on another website does not give attackers access to your Remitano account. it's almost like a 2FA login system since the user would have to access their email and click on the login link to access their accounts. Clearly, given the sensitivity of a Remitano user's account, the email login seems like a better option, especially in helping those who're prone to creating weak username/password combinations.

2. Two-Factor Authentication on Trades

image

This is a well-known feature of Remitano; it uses Authy Authenticator app to verify that it's a user initiating a sensitive functionality by asking for a One Time Password (OTP). The importance of this is that there are several things that could happen which may grant an unauthorized party access to your account and the funds in it. For example, if you misplaced your mobile phone and the thief somehow had access to it, or if you logged into Remitano on a public PC but forgot to logout, your Remitano account and its details become exposed to whoever possesses the device (phone/PC). The Authy 2FA app is also installed in your mobile phone which is in possession of someone else. However, because Authy requires a fingerprint verification to access the OTP, the attacker will not be able to transfer funds from your account, even though he/she has full access to your phone/PC. This is the essence of 2FA security; it verifies twice (that is access to your account--which the attacker has bypassed--and then, access to the Authy app--which the attacker cannot bypass due to the fingerprint verification).

3. Session Expiration

image

Photo Credit: CrackBerry Forum
You would have noticed that when using a browser on your mobile phone or PC, you get logged out of your account after a certain period of inactivity. This is a deliberate security measure to make sure an unauthorized party does not access your account. This control is useful in case of users who may have misplaced their devices or logged in on a public PC and left forgetting to log out. If the session is not expired and another users visits https://remitano.com, the user gets landed into the account of the person who last visited remitano.com. But if sessions are expired after some minutes/hours of inactivity, it reduces the likelihood of the occurrence alluded to above.

4. Warning About MITM

image

Photo Credit: Phoenixnap

Most users are unaware of MITM (Man-In-The-Middle) attacks. If you're using a corporate network, such as a router in an office or organization, you may be at risk of a MITM attack. An attacker can "sit" in between you and the website, in this case, remitano.com, such that he/she can monitor every page you visit, every transaction you perform, every 2FA OTP code you enter from Authy Authenticator app, etc. If you want to visit remitano.com, your internet traffic is first routed to the attacker who has placed himself between you and the website; he then makes any changes he intends to make including changing the account name and number of someone you intend buying bitcoins from and wanted to pay by bank transfer. What then shows on your browser in Remitano's website is the attacker's bank details not the seller's bank details. It's a feasible attack, and that's why Remitano always tell you to check to verify the name of the seller/buyer and the name of the bank account to make sure you're not in a Man-In-The-Middle scam. The warning is good and should be heeded to.

5. Partnering With HackerOne

image

Photo Credit: Remitano Blog Post

In one of Remitano's blog posts last month (December, 2020), Remitano partnered with security company HackerOne to ensure safety of users. This partnership allows skilled security researchers to help find bugs on Remitano platform before the bad guys do. It's actually a good practice even recommended by the US DOD and done by top companies such as Google, Facebook, Twitter, Coinbase, Binance, etc. This is a step forward. With more eyes on the security of Remitano, more bugs are likely to be found and fixed on time to ensure continuous safety of users.

So, these are five security measures you should know of; of course, there are several others which are in place. I believe we all have a better understanding of why some functionalities work the way they do. Cheers!

Maybe you are interested:

Comments (7)
Guest
atikarani14
6 years ago
👍
jalansultan
6 years ago
Good
bellagita_
6 years ago
Thanks info
yunan90
6 years ago
yes good
astina26
6 years ago
what should i do if i can't access my email?
iromaprince1
2 years ago
I can show you
dergun12
6 years ago
nice
Related posts
Discussion
• 2021/05/28
APPLE AND CRYPTOCURRENCY
Discussion
• 2021/05/27
MARKET CRASH UPDATE
Discussion
• 2021/05/27
WILL BITCOIN EVER BE WORTH $100,000?

Our newsletter

The latest cryptocurrency market news, technologies, and help resources.