Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

111–120 of 287 posts

Re: Coinbase Breach Notification

#111
post #39
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

> differentiate the coins at all from regular banking Apart from the fact that you can save value over time? Because the dollar is only going down.

You can verify that one bitcoin you have today will not be diluted by more than a certain amount tomorrow. Value is based on people’s value of the object though, and I wouldn’t necessarily bet on Bitcoin keeping that over the long term.

Re: Coinbase Breach Notification

#112
post #105
post #99

Earlier quoted context omitted.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

There are multiple ways to avoid this, such as using an app that saves those keys (eg Authy) or using recovery keys.

Re: Coinbase Breach Notification

#113
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Huh. 3 or so years ago, I got SIM-swapped and they ran away with my Coinbase crypto, and CB definitely never made me whole.

Re: Coinbase Breach Notification

#114
One thing that cryptocurrencies achieved is they introduced a private key authentication at scale. For a moment, there was a hope that we can move to private key authentication mechanism. But, unfortunately, it was quickly rolled back by introduction of custodial wallets and we got pulled back into world of passwords.

Re: Coinbase Breach Notification

#115
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

A point very well made by Mitchell and Webb: https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: Coinbase Breach Notification

#116
post #10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

Looking at his other comments, he's speculating. The document talks about obtaining an SMS verification token, they say "we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process", and have not removed SMS as an authentication option. I see no reason to think this vulnerability was a SIM swap. Him stating it as if it's a fact in his original comment is very misleading.

Re: Coinbase Breach Notification

#117
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

It was not a simswap/simjack attack, they exploited an oversight in coinbase's password-reset 2fa to send the challenge code for one user to another user's phone number.

Re: Coinbase Breach Notification

#118

Earlier quoted context omitted.

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

> which is much, much worse. This attack wouldn't have been possible if they didn't allow SMS 2FA, so I don't think that's fair to say at all.

What if the users had no 2fa at all? attackers still had their passwords and their emails, and their sms numbers

Re: Coinbase Breach Notification

#119
post #8

In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the informatio…

[deleted]

Re: Coinbase Breach Notification

#120
post #105

Earlier quoted context omitted.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

There are multiple ways to avoid this, such as using an app that saves those keys (eg Authy) or using recovery keys.

But then bad guy just logs in to Authy with the same stolen credentials because most normal people will probably use the same credentials for everything, including Authy. And arguably, the smartest tech-savvy folk wouldn't be storing their 2FA keys in the cloud like Authy anyway.

If your cloud account is protected by 2FA that's also in the cloud... it's turtles all the way down.

Post reply on HN