Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
71–80 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#72Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#73The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.
Unrelated, but for added spice, here's a thread from ten months where everyone agrees you're a fool unless you secure your coinbase account with google authenticator
https://www.reddit.com/r/CoinBase/comments/1h65zuh/account_h...
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#74How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.
A warning to auth engineers: if an account is using a Gmail address, then auth codes from Google Authenticator should not be considered a second factor.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#75Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#76Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)
The attacker had the passwords and 2fa codes from the Google account so Coinbase couldn't really distinguish them from the right person (tho presumably for large transfers they may require some extra checks, dunno)
> Google had cloud-synced my codes.
> That was the master key. Within minutes, he was inside my Coinbase account.
The author wrote "codes", not "passwords".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#77> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#78I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#79Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#80How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.
I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth engineers: if an account is using a Gmail address, then auth codes from Google Authenticator should not be considered a second factor.