315
submitted 1 year ago* (last edited 1 year ago) by rambos@lemm.ee to c/privacy@lemmy.ml

Hello nice people,

I've been using NiceHash app for some time 5-6 years ago. (It was a simple app for mining cryptocurrency and you get paid in bitcoin on their wallet, then you could transfer bitcoin to another wallet.) It was working fine until they got hacked (or fooled us) and lost all crypto. Luckily I didn't loose much like some guys did. I decided not to use the service anymore and I'm still receiving stupid e-mail newsletters. I tried to unsubscribe and It asks me for login, I know password, but don't have 2fa anymore. Also I don't have backup 16 words.

Now support told me that this is the only way and I feel ridiculous about taking selfie just to unsubscribe. Am I protected against this somehow? I live in Europe and I think Nicehash is located in neighbourhood.

And of course I never wanted to subscribe...and I don't think I ever verified account with a document.

What are my options other than just filtering that shitty domain as spam?

edit: typo

you are viewing a single comment's thread
view the rest of the comments
[-] pianoplant@lemmy.world 38 points 1 year ago

Probably an unpopular opinion - but I actually think requesting overriding 2fa is a big deal and companies shouldn't do that lightly. If I had a lot of money in crypto I would sure hope the exchange would scrutinize a request to turn off 2fa. And if op had saved their backup words they wouldn't have been in this situation.

Now requiring that to change an email subscription is not great, but again - turning off 2fa without the proper backup options should be difficult and scrutinized.

[-] Falmarri@lemmy.world 17 points 1 year ago

Requiring logging in to unsubscribe is absolutely bullshit. I mark all emails as spam that don't automatically unregister with ONLY clicking a lick. I'm not providing my email, I'm not logging in.

[-] pianoplant@lemmy.world 4 points 1 year ago

It's probably not for marketing emails. They probably require login to disable account alerts. Imagine a threat actor gets access to your account, turns of transaction alerts so you aren't notified, then transfers out all your crypto.

I'm certain the marketing emails don't require login to unsubscribe.

[-] kevincox@lemmy.ml 12 points 1 year ago

For bypassing 2fa this does seem reasonable. But anyone who can access the email address should have the permission to unsubscribe from messages.

For example on my service there is the concept of a "primary email" which is the only one that can be used to reset the password. But even if you have lost the password and access to your primary email you can still unsubscribe any other email from notifications as long as you can show access to that particular email. You won't regain access to the account but you can turn off emails.

this post was submitted on 27 Aug 2023
315 points (100.0% liked)

Privacy

31279 readers
664 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS