"Between March and May 20, 2021, you were a victim of a third-party campaign..." There were a spat of Coinbase SMS phishing texts in July 2021. So the window could be much longer, and the campaign ongoing.
Coinbase Breach Notification
161–170 of 287 posts
Re: Coinbase Breach Notification
#162> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…
> you have to admit that you are far more likely to be compensated in the event of an attack if you are using a large exchange This is only a recent phenomenon, and I don’t think it holds for all “large exchange[s]”.
Re: Coinbase Breach Notification
#163Earlier quoted context omitted.
> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…
Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.
The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforce strong factors for high balance users. You have to balance that against them taking their business elsewhere.
Re: Coinbase Breach Notification
#164Reminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://www.ledger.com/
Re: Coinbase Breach Notification
#165Earlier quoted context omitted.
What they should be doing, is to subsidise YubiKeys to their high-value customers. Not just to lock down the logins to Coinbase, but to also secure their customers' email, Twitter accounts, and as many other online systems as would support hardware backed WebAuthn. Hell, PokerStars did this with RSA tokens back in 2008 so it's not like it's a new idea.
I love my YubiKey but it doesn't work with my phone. Have newer models solved this problem?
Re: Coinbase Breach Notification
#166High security services should send a pair of U2F keys to each and every customer when they sign up (or hit a retention/value threshold), with instructions on how to store them (that is, different buildings). Then they can use normal app-based 2FA day to day (NOT TOTP as that is phishable), and use the preenrolled U2F hardware tokens as recovery methods when the user inevitably loses their phone and needs to re-enroll…
The other issue is that you ultimately need some sort of fallback mechanism if someone loses their keys. And it will happen. So you still end up with a process that can be socially engineered, which is generally the weak link in any authentication system.
Re: Coinbase Breach Notification
#167Re: Coinbase Breach Notification
#168I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…
If they were certain this was PURELY a phishing campaign against their users, then they had no need to disclose to the government.
Their wording in their disclosure is very very carefully crafted to not deny a breach of their data - pending "conclusive" evidence.
They made a choice to disclose so that the gov't could never claim that they failed to disclose should Coinbase data appear on a darknet website.
And While they make an allusion to social media data collection - I was a target in June, and I absolutely had ZERO social media talking about using coinbase. There is NO WAY hackers could have deduced on social media that I was Coinbase user, nor gotten my cell phone number.
I am 90% confident that Coinbase WAS breached directly, allowing hackers to gain access to email and phone number for my account.
This disclosure is 100% CYA.
Re: Coinbase Breach Notification
#169Earlier quoted context omitted.
> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…
I agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly. From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain. I would add that the users have some responsibility…
Re: Coinbase Breach Notification
#170Another reminder that text-based 2FA is not secure.
One thing I've become painfully aware of recently is how all MFA is rendered pretty insecure by various "fallback" processes. I recently switch jobs and realized I had a few accounts using my old work phone as SMS 2fa number. In every case it was ridiculously easy to call a CSR and get 2fa disabled from their end.