Hello nice people,

I’ve been using NiceHash app for some time 5-6 years ago. (It was a simple app for mining cryptocurrency and you get paid in bitcoin on their wallet, then you could transfer bitcoin to another wallet.) It was working fine until they got hacked (or fooled us) and lost all crypto. Luckily I didn’t loose much like some guys did. I decided not to use the service anymore and I’m still receiving stupid e-mail newsletters. I tried to unsubscribe and It asks me for login, I know password, but don’t have 2fa anymore. Also I don’t have backup 16 words.

Now support told me that this is the only way and I feel ridiculous about taking selfie just to unsubscribe. Am I protected against this somehow? I live in Europe and I think Nicehash is located in neighbourhood.

And of course I never wanted to subscribe…and I don’t think I ever verified account with a document.

What are my options other than just filtering that shitty domain as spam?

edit: typo

    • Astroturfed@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      3 years ago

      Don’t point out how all their bullshit requires middlemen and accounts holding their currency to make it work. That makes it looks silly. Almost like it’s just more complicated harder to use money that people can more easily steal from you.

      • jet@hackertalks.com
        link
        fedilink
        arrow-up
        2
        ·
        3 years ago

        I love talking to tech recruiters… We are a defi startup revolutionizing the financial world… “Cool, so distributed smart contracts, zero knowledge open source swarms?”… no, we run a centralized website where people give us money and we do a thing for them…

        Putting the central back in defi. It’s almost like their is willful ignorance in what their own words mean.

        • Astroturfed@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          Using buzzwords to describe doing something people have been doing for decades or centuries is all the newer big tech companies seem to do. They’re just fancy new middlemen with a shiny interface for us to use.

          • jet@hackertalks.com
            link
            fedilink
            arrow-up
            1
            ·
            3 years ago

            There are some really cool decentralized concepts that would be fun to work on. But only a tiny handful of companies actually do, it’s usually a open source group doing it.

            Makes me mad when I talk to the imposters

  • jet@hackertalks.com
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    I can’t speak for Europe, but a certified letter saying in no uncertain terms that you don’t wish to be contacted again, sent to their legal department should carry the day.

    If you have a lawyer friend, bonus points for saying all future correspondence must go through your legal representative, and no other methods (email, phone, sms) are welcome. I believe that notice carries legs in the US.

    In europe I suspect the GDPR should let you get all your data, and account removed without jumping through their hoops.

    • rambos@lemm.eeOP
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Thanks for the link. Feels bad tho 😭 gdpr gave me Accept/Reject cookies and some more pain as a bonus it seems 😂

      • Schlecknits@feddit.de
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        GDPR didn’t give you cookie banners, it’s shitty websites that do.

        If they were to just follow activated “Do not Track”-Preferences, they wouldn’t need to ask, instead they would deactived them by default. Or you could just not use cookies, it’s not like somebody forces you to give cookies out to your website’s users.

    • rambos@lemm.eeOP
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Also, Im not trying to delete account (but that eould be ideal), Im just trying to unsubscribe. I guess it doesnt matter here FML 😂

      • Schlemmy@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        They should unsubscribe you by simple request and only need your e-mail for that. You could verify by clicking a link in an unsubscribe email.

    • Blizzard@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      But if OP did not provide “selfie” during registration, providing it now doesn’t help confirming his identity so it doesn’t fall into that category. I would aks them how do they justify that and if they are trying to discouraged me from deleting the account.

    • Schlemmy@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      They can’t ask for more information than what they needed to create your account.

      But maybe they’re seen as a bank and then they have to confirm your identity with a copy of your id.

      • rambos@lemm.eeOP
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        Ive never heard of bank asking selfie. I wouldnt even provide ID, but that would make bit more sense

        • Kissaki@feddit.de
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          In Germany I’ve had multiple contracts that needed identification. They use trustworthy third party services for verification though.

          • rambos@lemm.eeOP
            link
            fedilink
            arrow-up
            1
            ·
            3 years ago

            Ive used face scanning on some other crypto service, but didnt know its a thing in banking. Thanks for sharing, but it still doesnt explain why I need that just to unsubscribe. I could accept that they are trying to protect me, but they obviously have diferent plans. My experience and recent communication with support proved NiceHash is ran buy toxic garbage and not by people who run a bank or anything close to that.

            • Schlemmy@lemmy.ml
              link
              fedilink
              arrow-up
              1
              ·
              3 years ago

              They need to be sure it’s you who’s unsubscribing, I suppose. There’s been enough social engineering to not rely on emails only.

              • rambos@lemm.eeOP
                link
                fedilink
                arrow-up
                1
                ·
                3 years ago

                I see that selfie is the only solution to unsubscribe (if not involving lawyer or just spam filter).

                I understand what you are saying, but If I lost my email why would they send newsletter to a new owner? It just makes no sense since 99% can be unsubscribed with no login or whatever they ask.

                Sorry, its hard to accept any safety meassure as explanation due to bad reputation of NiceHash. Also after talking to human support I just feel even less safe tbh, but it doesnt surprise me at all, its company that took my crypto back in a day.

                Ill try fake pic when I get some time to burn

    • rambos@lemm.eeOP
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      3 years ago

      It is in spam all the time, I just found some non-spam e-mails there. Trying to clean the folder a bit now

  • WhoRoger@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    If you asked to delete or alter the account, then it makes sense. To unsubscribe from emails… Well normally not but I guess it’s financial information, and you can’t use 2FA, so I guess it makes sense that they need to protect themselves.

    If you never used a document to sign up, then it’s ridiculous to ask for more information… Not sure if it’s actually illegal though, as long as they handle the data correctly.

    • rambos@lemm.eeOP
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      It would be less morbid if they were asking for documents, but selfie comon…

      They are not providing anything important to my email, its just crap like:

      Why should you overclock your GPUs? Help us make NiceHash better! Etc

      Im contacting them from the same email tho. Obviously company I dont trust and I have to stick to spam folder it seems

      • WhoRoger@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        Documents don’t help against identity theft. I guess selfies don’t either in the age of deepfakes, but it gives them plausible deniability.

        The problem here is that you lost the 2FA, so that makes it difficult.

        But yea as long as it’s just emails from a company you don’t care about, setting them as spam is the easiest solution.

  • StellarTabi [she/her]@hexbear.net
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    I’d setup a thing to auto-mark them as spam and forget about it. CAN-SPAM and FTC guidelines dictate that for non-transactional emails like newsletters, the user must be able to unsubscribe without a fee and without requiring a login. IDK anything about European law.

  • AnonTwo@kbin.social
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    I mean, just mark as spam?

    It hurts them more if a bunch of people mark them as spam and it becomes a trend doesn’t it? Just seems like a design issue on their part.

    I always figured that companies generally wanted to avoid that.

  • OrangeCorvus@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    That’s stupid and illegal in Europe since you only want to unsubscribe from emails. The few sites for which the unsub button does nothing, I usually contact them and tell them they are breaking the EU law and if they don’t stop, I will report them. Works all the time.

        • DessertStorms@kbin.social
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          In the UK there is Trading Standards and a relevant ombudsman (ofcom for communications for example), as well as the Information Commissioner’s Office for something specific like reporting a company for spam, there should be something similar wherever you are.

          In my experience a rude reminder to the company that you don’t want to receive their emails and that by not giving you an easy way to unsubscribe they are breaking the law and that you will (or have) reported them to the relevant bodies, is enough to get them to stop.

    • Piogre314@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      For anyone curious, it’s illegal in the US too, and you can threaten to report them to the FTC for violation of the CAN-SPAM act.

  • pianoplant@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    Probably an unpopular opinion - but I actually think requesting overriding 2fa is a big deal and companies shouldn’t do that lightly. If I had a lot of money in crypto I would sure hope the exchange would scrutinize a request to turn off 2fa. And if op had saved their backup words they wouldn’t have been in this situation.

    Now requiring that to change an email subscription is not great, but again - turning off 2fa without the proper backup options should be difficult and scrutinized.

    • Falmarri@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Requiring logging in to unsubscribe is absolutely bullshit. I mark all emails as spam that don’t automatically unregister with ONLY clicking a lick. I’m not providing my email, I’m not logging in.

      • pianoplant@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        It’s probably not for marketing emails. They probably require login to disable account alerts. Imagine a threat actor gets access to your account, turns of transaction alerts so you aren’t notified, then transfers out all your crypto.

        I’m certain the marketing emails don’t require login to unsubscribe.

        • jet@hackertalks.com
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          I was with you till your last sentence, I’ve seen multiple companies require account login to disable marketing emails. It’s a dark web pattern to keep their subscription numbers high, by adding a lot of friction to unsubscribing. Those companies can go fuck themselves, but they exist in numbers

    • kevincox@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      For bypassing 2fa this does seem reasonable. But anyone who can access the email address should have the permission to unsubscribe from messages.

      For example on my service there is the concept of a “primary email” which is the only one that can be used to reset the password. But even if you have lost the password and access to your primary email you can still unsubscribe any other email from notifications as long as you can show access to that particular email. You won’t regain access to the account but you can turn off emails.

      • jet@hackertalks.com
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        For marketing emails I totally agree.

        For important account security and verification emails, no I don’t think that should be done without being able to log into the account.

        If somebody breaks into your email, they shouldn’t be able to compromise everything silently

        • kevincox@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          This is a good point. Maybe you could have some sort of exit plan such as 3 emails confirming that you have been unsubscribed at 1d, 30d and 365d. This way if the email takeover is temporary then the user will eventually see a warning but there is still a finite amount of emails still to be received.

          It isn’t perfect, because an attacker could set up filters or something so that these aren’t noticed. But at this point the attacker could set up a filter to hide the regular account emails so it really isn’t any worse.

          • jet@hackertalks.com
            link
            fedilink
            arrow-up
            1
            ·
            3 years ago

            I think in most cases confirming you own the email should be sufficient to unsubscribe.

            In high security situations there should be a more extensive method, but it should still be possible. Perhaps the timed unsubscribe, i.e. a month of access. Or mailing a letter to the account holders address. (I.e. take 4 weeks to give the account holder time to opt out)

    • kevincox@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Yup. I try to unsubscribe nicely once. If it isn’t honored they are going straight on my provider’s spam list.

  • Schlemmy@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    Are they considered a bank? Because a be’abnk had to verify your identity and for that they can use a copy of your id.

  • uralsolo [he/him]@hexbear.net
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    If it’s just a newsletter I would set up a mailbox filter that just sends all of their mail to the trash. GMail makes this pretty easy (highlight a spam message, select “filter messages like these” from the top menu), but idk how to do it on other mail servers.

  • voxel@sopuli.xyz
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    well at least they provide this as an option. usually if you lose your 2fa, hardware keys (such as android phones) AND recovery codes, your account is gone. period.
    there’s literally no other way to confirm your identity without something like id or a credit card if your credentials are gone.

      • kevincox@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        That is your opinion. Personally if I have a password + 2FA configured for an account I don’t want anyone without access to those two things getting in. Ideally this would be configurable per-account, this way people who are fine trusting their email can do that and those who aren’t can not allow that.

        But it is a question of security versus access. Some people would rather lose access to an account than give someone else access.