Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

171–180 of 287 posts

Re: Coinbase Breach Notification

#171
post #39
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

> differentiate the coins at all from regular banking Apart from the fact that you can save value over time? Because the dollar is only going down.

people invest their money into appreciating assets like stocks

Re: Coinbase Breach Notification

#172

Earlier quoted context omitted.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

> I have a similar gripe against "identity theft", which really ought to be... ... bank robbery by unknowing proxy. If we reframed the narrative, I bet banks and financial institutions would bust their asses to make things better.

They already do for the most part though right? That is, they lose a huge amount of money to "identity theft" and have ample incentives to stop/prevent it.

Re: Coinbase Breach Notification

#173
What I'm getting from this is that Coinbase was/is using SMS-based 2FA? Using anything short of mandatory U2F means the responsibility of this breach firmly falls on Coinbase's shoulders. It's like if you found out your bank uses single-bolt doors for its vault.

Re: Coinbase Breach Notification

#174
post #130

Earlier quoted context omitted.

Keeping your life savings in cash under your mattress is more stressful than relying on a bank.

Do you need me to hold your hand when we cross the street?

I'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go.

Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target.

One of the main functions of government is private wealth protection. Banks are a feature, not a bug.

Re: Coinbase Breach Notification

#175
post #123

Earlier quoted context omitted.

I agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly. From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain. I would add that the users have some responsibility…

Telcos have no responsibility to stop SIM fraud. Telcos have communicated the last 30 years SMS is not secure (travels as plain text) and should not be used for 2FA. If companies have ignored this advise then it is on them.

And the elephant in the room is... the real purpose, for many corps eg Google, others, is to identify you, track you more accurately.

And your mobile phone number is invaluable here.

Re: Coinbase Breach Notification

#176
post #174

Earlier quoted context omitted.

Do you need me to hold your hand when we cross the street?

I'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go. Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target. One of the main functions of government is private wealth protection. Banks are a feature, not a bug.

And when they do and I do, I have a large cache of weapons and ammunition to wave at them with.

If you think the government is protecting your wealth, you're incredibly naive.

Re: Coinbase Breach Notification

#177

Earlier quoted context omitted.

The easiest way to prevent sim swap attacks is to use Google Voice. Google has no customer service, so there isn't anyone you can call up and con.

This isn't really true. Google Voice numbers are managed by bandwidth.com and have been taken by attackers submitting fraudulent number portability requests in the past.

Don't you have to login to your Google account to port a number?

Re: Coinbase Breach Notification

#178
post #175

Earlier quoted context omitted.

Telcos have no responsibility to stop SIM fraud. Telcos have communicated the last 30 years SMS is not secure (travels as plain text) and should not be used for 2FA. If companies have ignored this advise then it is on them.

And the elephant in the room is... the real purpose, for many corps eg Google, others, is to identify you, track you more accurately. And your mobile phone number is invaluable here.

coinbase does kyc. it already knows who you are

why sms? because everyone has it. we're not in a otp/u2f only world yet. sms 2fa is better than no 2fa

Re: Coinbase Breach Notification

#179
post #155
post #146

Earlier quoted context omitted.

Coinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process". [1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...

With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special…

If they use that wording, though, they are putting themselves on the hook to fix the "flaw". That's why I'm skeptical that it was just simjacking. I don't see a way that Coinbase could implement SMS 2FA in a way that doesn't have that "flaw".

Re: Coinbase Breach Notification

#180

What I'm getting from this is that Coinbase was/is using SMS-based 2FA? Using anything short of mandatory U2F means the responsibility of this breach firmly falls on Coinbase's shoulders. It's like if you found out your bank uses single-bolt doors for its vault.

Is there any d2c business anywhere in the world right now that requires U2F on all accounts? I think you underestimate how confusing all of this is to non-technical users.
Post reply on HN