Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

141–150 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#141

There should be an ISO standard with respect to how much power and information that front line customer support agents have. The more information you need, like changing passwords or accessing personal information, should get forwarded to higher level customer support agents with better training and more monitoring. This way you can design customer support experience with as little exposure to security issues as poss…

> better training and more monitoring.

That’s very load-bearing. It won’t help.

The CS reps are based in a LCOL country so the opportunity for theft is simply incredibly lucrative.

What is really needed, is customer-in-the-loop for access to their data. The problem is, not all accesses would make sense. Doing analytics over the data of the top 1% of customers, for example, requires some level of access, but would freak out those customers if they had to approve it.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#143
post #74
post #44

Interesting coincidence? >On April 12, Coinbase updated their user agreement to take effect TODAY, May 15, with new language about waiving some rights to class action lawsuits and jurisdiction selection. https://bsky.app/profile/jsweetli.bsky.social/post/3lp7sw647...

This should be illegal.

1 day after they were emailed.

Also, "Coinbase had detected the breach independently in previous months", aren't they required to disclose this? In the EU they are: Every EU institution must do this within 72 hours of becoming aware of the breach, where feasible

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#144
post #95

Earlier quoted context omitted.

Let's hear you repeat this position after your Coinbase account is compromised and you're looking for recourse.

You seem to believe that AML/KYC regulation exists to benefit customers or to prevent or recover from account compromises. It does not, and I have no idea why you would think it does. Something like a Yubikey or iris-scanning stations could help to prevent Coinbase account compromises, but AML/KYC regulations do not require or even encourage them, though perhaps someday they will.

You... want to replace KYC with iris scanning stations?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#145
post #59

Earlier quoted context omitted.

> What coinbase needs are IRL offices where you can go and do things like account recovery, and where people trying to steal money can be caught and prosecuted (and makes a huge barrier for the overseas thieves who are usually doing this) That's just a bank.

Correct. Coinbase is a bank that holds cryptocurrency.

And OpenSea is a zoo that holds apes.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#146

Maybe it’s a naive question, but in many breach reports I see things like 'No passwords, private keys, or funds were exposed.' How come companies can usually protect that kind of data, but not emails, names, and other personal info?

A properly implemented login system will never store a password in the first place. Properly hashed passwords can still be cracked in some cases, but if your password is strong and the hash is good, it’s safe.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#147
post #141

There should be an ISO standard with respect to how much power and information that front line customer support agents have. The more information you need, like changing passwords or accessing personal information, should get forwarded to higher level customer support agents with better training and more monitoring. This way you can design customer support experience with as little exposure to security issues as poss…

> better training and more monitoring. That’s very load-bearing. It won’t help. The CS reps are based in a LCOL country so the opportunity for theft is simply incredibly lucrative. What is really needed, is customer-in-the-loop for access to their data. The problem is, not all accesses would make sense. Doing analytics over the data of the top 1% of customers, for example, requires some level of access, but would fre…

If it would freak out the customers, maybe they shouldn’t be doing it.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#148
post #59

The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…

> What coinbase needs are IRL offices where you can go and do things like account recovery, and where people trying to steal money can be caught and prosecuted (and makes a huge barrier for the overseas thieves who are usually doing this) That's just a bank.

Watching crypto enthusiasts run into every problem that society already tackled with in the past when developing currency and its controls, and then coming up with solutions that look exactly the same as what dirty fiat currency uses, has been a source of much entertainment the past few years

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#149

Blog post is here: https://www.coinbase.com/blog/protecting-our-customers-stand... > We will reimburse customers who were tricked into sending funds to the attacker due to social engineering attacks. If your data was accessed, you have already received an email from no-reply@info.coinbase.com; all notifications went out at 7:20 a.m. ET on 5/15 to affected customers.

The no-reply is an interesting decision. I get how difficult it is to run a company like Coinbase (their biggest strength, centralized + customer support, is also what enables this social engineering), but feels like an odd choice.
Post reply on HN