Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

121–130 of 287 posts

Re: Coinbase Breach Notification

#122
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Question as they did not mention Sim Swap in the email. Was this confirmed somewhere? "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account".

I'm personally more familiar with incidents using SMS stealers (mobile malware) or use of SS7 vulnerabilites due to my job. Telcos in our country (europe) run tight security on SIM swaps.

I was surprised about their recommendation to use time-based OTPs. They basically have the same attack vectors as SMS minus independent channel sign-what-you-see capabilites.

Edit: Answer was in other comments

Re: Coinbase Breach Notification

#123
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

I agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly.

From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain.

I would add that the users have some responsibility for losing their emails/passwords, but my initial framing insufficiently demands responsibility for the service providers in this instance. The service providers should be expected to take all reasonable steps to prevent fraud on their platforms, and that should include extra scrutiny of SMS-based authentication mechanisms (e.g., identity verification). This is why Coinbase paid them back, accepting some responsibility for the fraud.

Re: Coinbase Breach Notification

#125
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Agree. Although I would like coinbase to move away from SMS 2fa

Using SMS 2FA is negligent, considering it’s been four+ years since NIST told the industry not to use it because it’s not safe.

(It’s also the only option offered by many US banks, which is a sad commentary on the level of tech innovation in finance in the USA.)

Re: Coinbase Breach Notification

#126
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

There are ways to mitigate, such as multisig wallet. For day to day, use a wallet with a small amount. When it's balance runs low, you can replenish the amount from your vault, that requires at least 2 signatures. Crypto is not about completely eliminating trust from the system, but rather being able to choose whom you trust and control, what a trusted party can do.

Re: Coinbase Breach Notification

#127

"Between March and May 20, 2021, you were a victim of a third-party campaign..." There were a spat of Coinbase SMS phishing texts in July 2021. So the window could be much longer, and the campaign ongoing.

Yes, I also received several obviously fake SMSs in June 2021, so the window is clearly longer than what they are saying.

Re: Coinbase Breach Notification

#128
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

if they did a SIM swap that means that they compromised the user's phone, if I'm not mistaken.

You are mistaken. A SIM swap is a compromise at the carrier, not the handset.

Re: Coinbase Breach Notification

#129
post #105
post #99

Earlier quoted context omitted.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

> and now you're locked out of your own account because you lost your second factor.

To verify someone's identity ("Identity Proofing") using Stripe Identity [1] costs ~$2. They support IDs from 33 countries, and have implemented fraud detection in the flow. If you were so paranoid as to defend against someone stealing your government issued ID (used in the proofing process), you could paper mail a OTP to physical address on file.

Does it suck and its the cost of no digital ID infrastructure in the US? Yes. Is it insurmountable? Not at all. At the end of the day, people are the weakest link, and we must fallback to meatspace trust anchors (in this case, possession of government provided ID that can be provided on demand with robust fraud detection mechanisms). You are who you are, and own what you own, not because of key material but because of the law.

[1] https://stripe.com/identity

Post reply on HN