Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

151–160 of 287 posts

Re: Coinbase Breach Notification

#151

Earlier quoted context omitted.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

The easiest way to prevent sim swap attacks is to use Google Voice. Google has no customer service, so there isn't anyone you can call up and con.

This isn't really true. Google Voice numbers are managed by bandwidth.com and have been taken by attackers submitting fraudulent number portability requests in the past.

Re: Coinbase Breach Notification

#152
post #69

Reminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://www.ledger.com/

Good advice, but I'll never buy another Ledger product after getting doxxed in their data leak(s): https://www.google.com/search?q=ledger+data+leak

In hindsight, I should've known better than to use PII in my account.

It scared me into exiting the space entirely.

Re: Coinbase Breach Notification

#153

Earlier quoted context omitted.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

> "being your own bank" is actually a terrifying and merciless burden It's amazing how many smart people take so long to realize why banks exist.

It's really similar to running your own email server.

Re: Coinbase Breach Notification

#154
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

> I have a similar gripe against "identity theft", which really ought to be...

... bank robbery by unknowing proxy. If we reframed the narrative, I bet banks and financial institutions would bust their asses to make things better.

Re: Coinbase Breach Notification

#155
post #146
post #140

Earlier quoted context omitted.

I haven't been able to verify these sort of claims any more than I've been able to speculate it was blanket telco Letters-of-Authorization (LoAs) [0][1] or classic SIM swaps that resulted in the account takeovers. I'm not claiming you're wrong, but given the timing of the LoA fraud and the attacks, it seemed likely to me that this was not an actual web vulnerability. What makes you believe a specific exploit like tha…

Coinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process". [1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...

With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny."

The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special technical abilities, and therefore they are likely. Since the onus is on Coinbase to do identity verification in account recovery, a large number of successful takeovers would be a "flaw" in their process, even if it's not a technical flaw (which I would expect to be expressed in language like "vulnerability").

Accepting untrusted, unauthenticated user input as a SMS verification number would be a serious login-related flaw, and certainly Coinbase pentests their login pages. Any competent pentester would discover such a flaw. So between "Coinbase shipped a critical and obvious login flaw to prod" and "a routine and common criminal tactic was employed successfully against them," I find the latter more likely.

[0]: https://news.ycombinator.com/item?id=28720101

[1]: https://news.ycombinator.com/item?id=28720520

[2]: https://xkcd.com/2176/

Re: Coinbase Breach Notification

#156
post #145

Earlier quoted context omitted.

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

What they should be doing, is to subsidise YubiKeys to their high-value customers. Not just to lock down the logins to Coinbase, but to also secure their customers' email, Twitter accounts, and as many other online systems as would support hardware backed WebAuthn. Hell, PokerStars did this with RSA tokens back in 2008 so it's not like it's a new idea.

I love my YubiKey but it doesn't work with my phone. Have newer models solved this problem?

Re: Coinbase Breach Notification

#157
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Funny that Canada is the other way around (gov.ca)

Re: Coinbase Breach Notification

#158
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Attackers did not have to perform a sim-swap attack.

Coinbase provided a refund of the dollar value of the assets when they were taken, _not_ a return of the same assets.

I’d appreciate if you update your comment to be accurate; though I fully understand that you are being intentionally dishonest out of disrespect to HN users. And I fully understand that dishonest comments like yours are considered to be absolutely acceptable by Dan Gackle.

Re: Coinbase Breach Notification

#159
post #105
post #99

Earlier quoted context omitted.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Which works fine until they buy a new phone and trade in or reset the old one without transferring the private keys -- and now you're locked out of your own account because you lost your second factor.

Emergency single-use codes. They can be printed and stored in a safe. Not every service with 2FA has this feature, I have no idea why. How hard could it possibly be?

Re: Coinbase Breach Notification

#160

Earlier quoted context omitted.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

A point very well made by Mitchell and Webb: https://www.youtube.com/watch?v=CS9ptA3Ya9E

This is brilliant.
Post reply on HN