Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

11–20 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#11
post #8

Coinbase is not a Bitcoin wallet any more than your bank is a USD (whatever your local currency is) wallet. This has no relevance to Bitcoin wallets.

Well, Coinbase provides what it calls Bitcoin wallets. But yes, they're just accounts, which control Bitcoin wallets.

Still, this is what many have come to think of as Bitcoin wallets.

Me, I only use local wallets. If I had lots of Bitcoin, they'd be offline.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#12
post #3

Arg. I wish this article were more substantive, since it's an important topic. But there are no details.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it. SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth. It's not just SS7 vulns but also number portability. afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

The problem with two factor authentication is that it often turns to be just a two stage authentication, or, effectively, an SMS-only authentication.

I'm surprised that Googler still kept unsecure password reset on 2FA, while disabling it on regular accounts.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#15
Sadly, as far as I know, Paypal only allows SMS. I believe business account, you cannot link your Paypal to Braintrees and thus you cannot use any 2-auth authenticator.

If I am wrong, please correct me, but I see no other options on Paypal, which is ridiculous, considering Paypal is such an important service. SMS should not be used for any critical services, but in cases like Paypal there is no choice.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#16
post #10
post #3

Earlier quoted context omitted.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it. SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth. It's not just SS7 vulns but also number portability. afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

Maybe it's time for SSMS? The extra S being for secure, of course. Something encrypted and requiring authentication would be good - and maybe (tangentially related) not letting just anyone transfer your phone number to a new phone contract. That should require ID and some level of additional authentication. It's like the whole thing is a house of cards. I'm half amazed that it works as well as it does and isn't explo…

Better 2FA exists.

We still need better identity authentication. Copied passports, phone numbers, and email all have problems. There are government initiatives (in the US it seems to be NSTIC and login.gov). This should be opened up and made international. It seems that login.gov is already an OpenID identity provider. So only marketing is left. Next to login with Facebook and Google, there should be a "login with GovID" or however it is called. It has to work automatically for any citizen in any country (whose government participates), so UX is critical.

While blockchain is the hipster technology and there are people working on that (e.g. Civic), I cannot believe in adoption unless government is involved.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#17
How many times do we have to read that X is vulnerable to SS7 attacks? This has been going for the last couple of years.

SS7 in itself is huge disaster, I can recommend the following presentations: https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271... and https://media.ccc.de/v/31c3_-_6531_-_en_-_saal_6_-_201412272...

tldr: everything that uses sms is vulnerable.

edit: as others already mentioned, use offline 2fa like google authenticator.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#18
post #11
post #8

Coinbase is not a Bitcoin wallet any more than your bank is a USD (whatever your local currency is) wallet. This has no relevance to Bitcoin wallets.

Well, Coinbase provides what it calls Bitcoin wallets. But yes, they're just accounts, which control Bitcoin wallets. Still, this is what many have come to think of as Bitcoin wallets. Me, I only use local wallets. If I had lots of Bitcoin, they'd be offline.

I think it's important to hammer in the distinction into the minds of the public. The takeaway being that one should not treat coinbase as a wallet and thus should never leave coin in their accounts.

For example my boss lost coin trusting it in the hands of coinbase. He has contacted support to no avail. And there are no legal reprecussions for them doing this, just as Paypal reserves the right to freeze or steal your assets.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#19
post #13

Cryptocurrencies offer unprecedented transaction speeds Lol.

Good point.

Some payment processors credit sellers with just one confirmation. But it can still take several minutes, or more if your wallet client doesn't add enough fee.

Also, with Bitcoin price so high, fees are absurd for small transactions. That's the real problem.

For large transactions, on the other hand, Bitcoin is faster than wire transfer. I can move thousands of USD in a few hours, anonymously through a mixing service. For ~2% fee. There is the risk of price volatility, I admit.

Edit: Sorry, I didn't specify international transfers.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#20
post #19
post #13

Cryptocurrencies offer unprecedented transaction speeds Lol.

Good point. Some payment processors credit sellers with just one confirmation. But it can still take several minutes, or more if your wallet client doesn't add enough fee. Also, with Bitcoin price so high, fees are absurd for small transactions. That's the real problem. For large transactions, on the other hand, Bitcoin is faster than wire transfer. I can move thousands of USD in a few hours, anonymously through a mi…

Last month I moved £10,000 between two UK banks and it settled in 3 seconds. Fees were £0.00.

I could have moved more for exactly the same fee of free.

Post reply on HN