[bitfolk] Mass (50+ domains) DNS hosting at BitFolk

Top Page

Reply to this message
Author: Andy Smith
Date:  
Old-Topics: Re: [bitfolk] Proving that you are you
Subject: [bitfolk] Mass (50+ domains) DNS hosting at BitFolk

--aObFJ3I/fcifeQec
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi Kai,

On Sat, Jul 07, 2012 at 06:56:35PM +0200, Kai Hendry wrote:
> Brain fart: An advance payment from the customer with a matching name
> might prove identity in this last resort scenario.


So just to be clear, if YOU had disabled password reset and YOUR
service was down, you would not regard a scan of a utility bill as
sufficient, and would want me to tell you to make a payment by the
same means that you usually do before giving you a new password?

Cheers,
Andy

--=20
http://bitfolk.com/ -- No-nonsense VPS hosting

--aObFJ3I/fcifeQec
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEAREDAAYFAk/4cO4ACgkQIJm2TL8VSQvBfgCgoDfrlGNtvzK8zXFo9amqedeo
qKEAoLUjZrV+9gh/8oDRe4ElGVX/Q7/6
=IQFj
-----END PGP SIGNATURE-----

--aObFJ3I/fcifeQec--


From aaron@??? Sat Jul 07 17:25:36 2012
Received: from phoenixsupport.org ([2001:ba8:1f1:f1de::f5:c]
    helo=server02.filesanctuary.net)
    by mail.bitfolk.com with esmtp (Exim 4.72)
    (envelope-from <aaron@???>) id 1SnYlE-00028t-D2
    for users@???; Sat, 07 Jul 2012 17:25:36 +0000
Received: from [192.168.0.10]
    (cpc1-stkn14-2-0-cust232.11-2.cable.virginmedia.com [86.30.8.233])
    by server02.filesanctuary.net (Postfix) with ESMTPSA id 24C4B8A34C;
    Sat,  7 Jul 2012 18:25:36 +0100 (BST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=unadopted.co.uk;
    s=2012; t=1341681936;
    bh=f1kbbNlGn5qtHWzAQt6m2VOod4L6lnKANQa8NS0Claw=;
    h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject:
    MIME-Version:Content-Type;
    b=WL7MnQtoY3E47zxlF3Exl2llWBRCNkze56JatSryij1kJ8orFLQSUXIkiO26CFFSE
    nTXXGeyvKo94znxhEfcAdzloGIlxE2apqUj+PT360cUN2j5i2zneckasKbpZsqxUhh
    WAf/gt0PBJZbh5qhbHKv0bUs01yBFGaWLHXftYpY=
Date: Sat, 7 Jul 2012 18:25:35 +0100
From: "Aaron B. Russell" <aaron@???>
To: Andy Smith <andy@???>
Message-ID: <A133170A89B641238EE6876E7C46CFD8@???>
In-Reply-To: <3B35605E52F04AE2817487EE7C3EE903@???>
References: <20120707130537.GA11695@???>
    <ECAE67DBAB7C44C2BA99DA232CC6E395@???>
    <E8D012CEB3584285925AD3F1476D118B@???>
    <20120707170729.GU3867@???>
    <3B35605E52F04AE2817487EE7C3EE903@???>
X-Mailer: sparrow 1.6.1 (build 1081.52)
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="4ff8710f_11b1cc33_8726"
X-Virus-Scanner: Scanned by ClamAV on mail.bitfolk.com at Sat,
    07 Jul 2012 17:25:36 +0000
X-SA-Exim-Connect-IP: 2001:ba8:1f1:f1de::f5:c
X-SA-Exim-Mail-From: aaron@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
    spamd2.lon.bitfolk.com
X-Spam-Level: 
X-Spam-ASN: 
X-Spam-Status: No, score=-1.0 required=5.0 tests=ALL_TRUSTED,SHORTCIRCUIT
    shortcircuit=ham autolearn=disabled version=3.3.1
X-Spam-Report: * -0.0 SHORTCIRCUIT Not all rules were run,
    due to a shortcircuited rule
    * -1.0 ALL_TRUSTED Passed through trusted hosts only via SMTP
X-SA-Exim-Version: 4.2.1 (built Mon, 22 Mar 2010 06:51:10 +0000)
X-SA-Exim-Scanned: Yes (on mail.bitfolk.com)
Cc: users@???
Subject: Re: [bitfolk] Proving that you are you
X-BeenThere: users@???
X-Mailman-Version: 2.1.13
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
    <mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
    <mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Sat, 07 Jul 2012 17:25:36 -0000


--4ff8710f_11b1cc33_8726
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

> So are you saying that if
>
> - YOU had disabled the password reset, and
> - YOUR service were down, and
> - you were communicating with me via email (possibly from a
> different email address to the one in our database)
>
> YOU would not want me to reset your account password based on an
> image of a utility bill, but would insist upon a government ID that
> I recognise?
>
>
>



To clarify: if there is a better solution than a government ID image, then let's explore those options. But being able to gain access to my account by supplying a potentially 'shopped utility bill seems risky to me.
--
Aaron B. Russell
http://unadopted.co.uk
+44 20 3137 4147








--4ff8710f_11b1cc33_8726
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printa