Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

101–110 of 287 posts

Re: Coinbase Breach Notification

#101

Earlier quoted context omitted.

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

Ok before I was locked out of my account for changing phone numbers they only had SMS

You can change your phone number by re-validating your identity. During the 2FA step when logging in, you can click on "I need to change my phone number" (or similar).

Re: Coinbase Breach Notification

#102
post #10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

These days in infosec circles simply having SMS-based 2FA enabled is now considered a no-no because of the notoriously bad (and inconsistent) security measures at large mobile carriers.

Re: Coinbase Breach Notification

#103
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> ... the attackers had to perform a "SIM swap" type attack on the users

Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure.

I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false identity" - however, that framing is necessary to make consumers accept, by default, the burden of clearing debts they were never party to simply because the defrauded party did not have adequately verify perpetrators identity.

Re: Coinbase Breach Notification

#104
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

Some exchanges have good customer service, but Coinbase isn't one of them. They went the route of minimizing customer support staff that many tech companies do.

Re: Coinbase Breach Notification

#105
post #99

Earlier quoted context omitted.

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

Re: Coinbase Breach Notification

#106

Earlier quoted context omitted.

Coinbase is not an unregulated free-for-all. They are licensed in all 50 states, and is registered as an MSB with FinCEN. https://www.coinbase.com/legal/licenses

That page does not list all 50 states, just FYI.

states not listed: California, Hawaii, Indiana, Massachusetts, Missouri, Montana, Utah, Wisconsin, and Wyoming

Re: Coinbase Breach Notification

#107
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

> "being your own bank" is actually a terrifying and merciless burden

It's amazing how many smart people take so long to realize why banks exist.

Re: Coinbase Breach Notification

#109
post #105
post #99

Earlier quoted context omitted.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

No problem, just reset your factor over SMS!

Re: Coinbase Breach Notification

#110
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

if they did a SIM swap that means that they compromised the user's phone, if I'm not mistaken.
Post reply on HN