Reminder that cliches are cliche for a reason: not your keys, not your crypto
Crypto.com accounts had unauthorized withdrawals
81–90 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#82Earlier quoted context omitted.
Maybe, but I think you can make a case for the opposite too. Without exchanges, there'd be no crypto. Exchanges are the only reason 99% of people who have crypto can figure out how.
Especially with mobile devices taking over. An increasing number of people don't even have a laptop or desktop to hold a whole blockchain on. Even an iPhone 13 Pro with 1TB of storage would lose 10-20% of its space to that. That isn't going to improve. The more popular it gets, the faster it grows, and it would compete with all the other storage needs that also grow. Get someone to load up and maintain a whole blockc…
A pruned full node downloads and validated all blocks, then discard everything not relevant to its own wallet.
A variety of “light clients” are also available for most chains, which fetch transaction data from peers as needed (usually using something like bloom filters to increase privacy).
Most ethereum apps just go through Infura. That’s a horrible centralized single point of failure that I’m not advocating, but the point is there are many ways a wallet app can connect to a remote full node.
Re: Crypto.com accounts had unauthorized withdrawals
#83Re: Crypto.com accounts had unauthorized withdrawals
#84Re: Crypto.com accounts had unauthorized withdrawals
#85Earlier quoted context omitted.
Time to play the classic crypto exchange game: hack or exit scam? Disabling 2FA in this scenario is dumb enough to raise the question of malfeasance of the part of this theft.
Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...
Re: Crypto.com accounts had unauthorized withdrawals
#86Earlier quoted context omitted.
> For context, this is the startup that has been using Matt Damon as it’s face. They're also notable lately for getting the naming rights to the (former) Staples Center. > https://en.wikipedia.org/wiki/Crypto.com_Arena
They took out huge ads in Vegas for re:invent. Personally that set my alarm bells off pretty badly.
Re: Crypto.com accounts had unauthorized withdrawals
#87Re: Crypto.com accounts had unauthorized withdrawals
#88> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…
That was exactly my question when I read this. How do they establish trust, when 2FA is revoked? How they prevent that the bad guy enables now 2FA and the god guy is locked out of his account? May the god guy didn't get the message that Crypto.com had an issue, because s/he is unavailable.
IE: single factor resets, so a compromised “2FA” was actually keys to the kingdom?
But you’d think the attacker would need access to a user’s email or some such then.
Re: Crypto.com accounts had unauthorized withdrawals
#89It seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive
Re: Crypto.com accounts had unauthorized withdrawals
#90> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…
I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.
But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it.
Anyone know how the do auth on the app?
For users in the US there is no way to change the password, because the webapp (which might have that feature) is not allowed to be used from US.
Once I asked how to change password and support said I can change the PIN on phone and dont worry your funds are safe.