Earlier quoted context omitted.
crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it. Anyone know how the do auth on the app? For users in the US there is no way to…
> crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. If you're speaking from experience as a user of their service, I strongly suggest that you use a different exchange. Gemini + Coinbase both have very easy-to-understand authentication systems. If you don't understand the authentication system, that's a good red-flag that you should take as a reason to move to…
Crypto.com accounts had unauthorized withdrawals
281–290 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#282Earlier quoted context omitted.
Its cliche, but it doesn’t really mean that crypto.com or any other crypto exchange isn’t on the hook for stolen funds. Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability. Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind) But in the real world, if you use a crypto exchange in a reasonable locatio…
So in the real world when using a regulated crypto exchange, what's the point of a blockchain other than asset speculation (which can also be done through traditional trading instruments at this point)?
Re: Crypto.com accounts had unauthorized withdrawals
#283It seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive
Re: Crypto.com accounts had unauthorized withdrawals
#284Earlier quoted context omitted.
Tornado Cash is a smart contract system that allows you to send fixed denominations of Ethereum, and receive a cryptographic "note" that allows someone who knows the note to withdraw the same amount of Ethereum from the smart contract. Since zero-knowledge cryptography is used to ensure the generated note cannot be linked to the depositing transaction, it can be used to send money to yourself or another person withou…
Interesting! I’m surprised the regulated exchanges don’t blacklist coins connected to that smartcontract because of the ease of facilitating laundering.
To expand on that, say someone withdraws ETH from Tornado cash and purchases an NFT with it. The seller of the NFT then swaps their ETH for USDC on a decentralized exchange (the ETH then goes into a pool). Later, a liquidity provider to the ETH/USDC pool withdraws liquidity from that pool, and sends their ETH to an exchange, let's say Binance. If Binance blocked such deposits (and especially if they did so without refunding the user on-chain), no one would use Binance, and they'd also be the target of a lot of lawsuits.
Re: Crypto.com accounts had unauthorized withdrawals
#285Earlier quoted context omitted.
> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…
Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.
Re: Crypto.com accounts had unauthorized withdrawals
#286Earlier quoted context omitted.
I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.
This is a common play in several industries. Art of Shaving markets itself well to casual people interested in traditional shaving products but they take regular products, mark them up by a lot, rebrand and then upsell. Nobody claims Art of Shaving is the apex of shaving. Best Buy does similar marketing in regard to electronics, but Best Buy certainly isn't the apex of electronics retailers. What makes you think cryp…
Re: Crypto.com accounts had unauthorized withdrawals
#287Earlier quoted context omitted.
This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
> This company is literally at the apex of the crypto industry Cryptocurrency was not even supposed to have these pseudobanks called exchanges leading this space. It wasn't even supposed to be an "industry". People were supposed to mine cryptocurrency on their own commodity hardware and use that to transact amongst themselves.
Re: Crypto.com accounts had unauthorized withdrawals
#288Earlier quoted context omitted.
This... Is literally how banks work.
Banks do not work this way. Banks have insurance policies, both private and federal, that would cover the losses.
Re: Crypto.com accounts had unauthorized withdrawals
#289Earlier quoted context omitted.
Of course it matters. Even if we assume someone figured out how to own the 2FA system, that knowledge doesn't magically make its way into the brain of every script kiddy capable of credential stuffing a login form. They're two totally different vectors with different surface area.
My thought is that it’s not really 2FA, and 2FA means temporary tokens, and there’s a method to gain entry with just login+token, e.g. via password reset.
If you want to deliver security then MFA is an interesting strategy that needs careful consideration and planning, you might end up building things like Security Keys so as to solve real threats. You might fix real problems (Google eliminated phishing) at your organisation.
But if your goal is to bamboozle fools into giving you their real money in exchange for Itchy and Scratchy money that you may or may not then "lose" then you don't need all that hard work. Take whatever nonsense you cobbled together and say it's "Two factor" because that means "good" to people who don't know any better.
Re: Crypto.com accounts had unauthorized withdrawals
#290> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…
Is anyone else getting the feeling from this press release that it seems they actually don't (yet?) know how their previous 2FA system was circumvented by the attackers?
As a communications person, reading between the lines tell me they've got no idea what happened. Comforting!