> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure. Can someone setup, test and rollout a _completely new_ authentication system in 3 days?
Crypto.com accounts had unauthorized withdrawals
141–150 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#142Earlier quoted context omitted.
Presumably they mostly stole ETH because tornado cash is the best mixer around to launder stolen funds
I'd love to read more about these money laundering operations like Tornado Cash. Are they just straight up 100% fraud companies? Do they have any pretense of a legitimate use case or does everyone just understand they're used for criminal activity? Are they regulated at all? I assume you have to trust your magic beans to them at some point; do the money launderers sometimes just steal them? What do they charge for th…
Check out their code on github.
Re: Crypto.com accounts had unauthorized withdrawals
#143Earlier quoted context omitted.
Wouldn't this also allow an attacker to add his own 2FA?
This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
Re: Crypto.com accounts had unauthorized withdrawals
#144Earlier quoted context omitted.
> SMS as a 2FA option I hope not, if that is true. The year is 2022 and companies managing >$100B in assets are STILL using SMS 2FA for protecting their life savings, despite SIM hijacking and SIM swapping still about. Quite pathetic really.
These companies want more cash heavy users. Like those older than 50. There is absolutely no way my parents could figure out 2fa in any way other than phone call/sms. They would be cutting out the less technical crowd, which is exactly who they're trying to convince to buy in
Re: Crypto.com accounts had unauthorized withdrawals
#145Earlier quoted context omitted.
And so what are we going to do as a society with these stolen funds? Playing a wallet mixing tracking game is a rat race and a waste of energy, otherwise we need a centralized system [on an immutable blockchain] to keep track of stolen funds, to then cross-reference every transaction with at point of sale/transfer - to then prevent it, no? If not a centralized solution like above then what? We just allow stolen funds…
There's no centralized system to track stolen dollars (at least not in the sense you're talking about), so I don't know why crypto would necessarily need one.
Re: Crypto.com accounts had unauthorized withdrawals
#146Earlier quoted context omitted.
And so what are we going to do as a society with these stolen funds? Playing a wallet mixing tracking game is a rat race and a waste of energy, otherwise we need a centralized system [on an immutable blockchain] to keep track of stolen funds, to then cross-reference every transaction with at point of sale/transfer - to then prevent it, no? If not a centralized solution like above then what? We just allow stolen funds…
There's no centralized system to track stolen dollars (at least not in the sense you're talking about), so I don't know why crypto would necessarily need one.
Re: Crypto.com accounts had unauthorized withdrawals
#147Earlier quoted context omitted.
I hope this doesn't mean we have to endure 20 years of this name on the nba court. With all this gambling (sports betting) sponsoring of the NBA and now these crypto sponsors, it really does look like the NBA has sold out (also new trikot sponsor deals). It's a shame how much they feast on hooking impressionable men on gambling. Actually, thinking about it, there should be more ads for f2p/mobile games, would fit per…
You'll have to endure it if you believe that Crypto.com will exist 20 years from now. I'd bet even money they won't exist in 5 years and the court is renamed in ~3 years. I mostly agree on the gambling front too - gambling was bad enough when you had to lure people to a casino but at least that gave them the excuse of "It's my form of entertainment, it's like going to a nightclub." "The best minds of my generation ar…
For some historic context, Enron Field lasted two seasons and CMGI Field less than one, from what I can tell? I wonder who holds the record.
Re: Crypto.com accounts had unauthorized withdrawals
#148Earlier quoted context omitted.
How is this a single point of failure? The issue was limited to a subset of users keeping funds in a Crypto.com wallet. Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
It is the implementation. I believe in bitcoin, works well and I don't blame the consumer for the producer's problems when it comes to power. But exchanges have become a key part of the implementation. That's not the real issue though. The issue is the _need_ for exchanges. They provide a host of services, mostly all of which are antithetical to the loftier ideals espoused by bitcoin. Too many crypto fans waltz passe…
Given the transaction fees needed for a distributed-enough network, and the bureaucracy needed when trading, it is not very useful as a currency, at least not for small payments, excluding Lightning.
So it's a commodity.
Re: Crypto.com accounts had unauthorized withdrawals
#149Earlier quoted context omitted.
I wouldn't call it a startup, it paid 700mil$ to rename an arena!
Venture capital used to be about placing small, diverse bets on a lot promising startups - everybody in the process was trying to make the world a better place Since about 2018, VC game changed - now it's about brazenly placing massive bets on a small set of startups of increasingly questionable utility, using the funds and clout to ram their way through into monopoly positions. Not a speck of morality involved anymo…
I think "everybody" here is a pretty substantial overstatement. Plenty of folks were just trying to make money, without much regard for whether it made the world better or worse.
Re: Crypto.com accounts had unauthorized withdrawals
#150> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…
This may be their only risk monitoring system. I’ve seen many DR plans that had this kind of detail written up in “consultant speak” with a straight face. Where they would detect server crashes by users calling them and their systematic method to failover was to manually rebuild.