Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

181–190 of 287 posts

Re: Coinbase Breach Notification

#181
post #149

High security services should send a pair of U2F keys to each and every customer when they sign up (or hit a retention/value threshold), with instructions on how to store them (that is, different buildings). Then they can use normal app-based 2FA day to day (NOT TOTP as that is phishable), and use the preenrolled U2F hardware tokens as recovery methods when the user inevitably loses their phone and needs to re-enroll…

At this point I think the thing holding back U2F is just user experience. It is not "hard" but it is a pain in the ass and most people just find it annoying. The other issue is that you ultimately need some sort of fallback mechanism if someone loses their keys. And it will happen. So you still end up with a process that can be socially engineered, which is generally the weak link in any authentication system.

The pain in the ass is why it should be used as an primary app-based 2FA recovery mechanism.

Doing 2FA via app is fine for most users. The failures happen when users lose their phone and need to reset 2FA. That's where the pain in the ass (but secure pain in the ass) of U2F would come in handy, to re-enroll primary 2FA.

Nobody presently has good ways of doing 2FA resets. U2F hardware is a near-perfect solution.

Re: Coinbase Breach Notification

#182
post #123

Earlier quoted context omitted.

I agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly. From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain. I would add that the users have some responsibility…

Telcos have no responsibility to stop SIM fraud. Telcos have communicated the last 30 years SMS is not secure (travels as plain text) and should not be used for 2FA. If companies have ignored this advise then it is on them.

SIM swapping also allows you to intercept voice calls, which are encrypted and supposed to be secure. The idea that telcos have no responsibility to stop people from taking over the telephone number that customers pay for is completely absurd. Moreover, often the SIM swapping is done by employees of the Telco itself using company infrastructure.

Re: Coinbase Breach Notification

#183

What I'm getting from this is that Coinbase was/is using SMS-based 2FA? Using anything short of mandatory U2F means the responsibility of this breach firmly falls on Coinbase's shoulders. It's like if you found out your bank uses single-bolt doors for its vault.

Is there any d2c business anywhere in the world right now that requires U2F on all accounts? I think you underestimate how confusing all of this is to non-technical users.

Plenty of banks require HOTP dongles. Those are, if not more confusing, than certainly on par with U2F dongles. Meaning if banks can do HOTP, they can do U2F, and using "confusing to consumers" is not an excuse.

Re: Coinbase Breach Notification

#184

Earlier quoted context omitted.

Is there any d2c business anywhere in the world right now that requires U2F on all accounts? I think you underestimate how confusing all of this is to non-technical users.

Plenty of banks require HOTP dongles. Those are, if not more confusing, than certainly on par with U2F dongles. Meaning if banks can do HOTP, they can do U2F, and using "confusing to consumers" is not an excuse.

Which banks require an HOTP dongle for customers. Maybe it is a non-US thing but I have never once seen that.

Re: Coinbase Breach Notification

#185
post #181

Earlier quoted context omitted.

At this point I think the thing holding back U2F is just user experience. It is not "hard" but it is a pain in the ass and most people just find it annoying. The other issue is that you ultimately need some sort of fallback mechanism if someone loses their keys. And it will happen. So you still end up with a process that can be socially engineered, which is generally the weak link in any authentication system.

The pain in the ass is why it should be used as an primary app-based 2FA recovery mechanism. Doing 2FA via app is fine for most users. The failures happen when users lose their phone and need to reset 2FA. That's where the pain in the ass (but secure pain in the ass) of U2F would come in handy, to re-enroll primary 2FA. Nobody presently has good ways of doing 2FA resets. U2F hardware is a near-perfect solution.

It's a near perfect solution assuming nobody ever loses their U2F device.

Re: Coinbase Breach Notification

#186
post #69

Reminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://www.ledger.com/

I must be missing something, but can someone explain what's the point of a hardware wallet? Why not just use a password manager?

Hardware wallets seem to have so many downsides, as far as I can understand.

You can keep multiple copies of your password manager's database (something like a kbdx file), but you won't have multiple copies of the hardware wallet. Therefore a single point of failure. If the wallet is stolen, damaged in a house fire, crushed by some accident etc. you're done. Also, can't the firmware of the hardware wallet possibly have some unknown bugs that might cause some failure in the future? Is the hardware failure-proof? No possibility of manufacturing defect etc.?

Secondly you've to buy a hardware wallet and whatever the cost, it's not free. Whereas an open source password manager like keepass is completely free (as in freedom as well as beer).

Re: Coinbase Breach Notification

#187

What I'm getting from this is that Coinbase was/is using SMS-based 2FA? Using anything short of mandatory U2F means the responsibility of this breach firmly falls on Coinbase's shoulders. It's like if you found out your bank uses single-bolt doors for its vault.

The fact that there’s no OTP option even available is what bothers me. Let the power users use OTP if they want it.

When OTP is available I always remove my phone and use that. Sim swap is such a common attack these days.

Re: Coinbase Breach Notification

#188
The attack still goes on. Email today:

    Coinbase

    Coinbase 
    Verify your email address
    In order to continue  using your Coinbase account, you need to reconfirm 
    your email address. To avoid service interruptions verify your email.
    Verify Email Address 
    

    If you did not sign up for this account you can ignore this email and the
    account will be deleted.

    Get the latest Coinbase App for your phone
    Coinbase iOS mobile bitcoin wallet
    
    Coinbase Android mobile bitcoin wallet
    
Whois info:

> whois plesk.page

    Domain Name: plesk.page
    Registry Domain ID: 41B85291E-PAGE
    Registrar WHOIS Server: whois.namecheap.com
    Registrar URL: https://www.namecheap.com/
    Updated Date: 2021-07-10T14:00:29Z
    Creation Date: 2020-03-18T03:06:27Z
    Registry Expiry Date: 2022-03-18T03:06:27Z
    Registrar: Namecheap Inc.
    Registrar IANA ID: 1068
    Registrar Abuse Contact Email: abuse@namecheap.com
    Registrar Abuse Contact Phone: +1.6613102107
    Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
    Registry Registrant ID: REDACTED FOR PRIVACY
    Registrant Name: REDACTED FOR PRIVACY
    Registrant Organization: Privacy service provided by Withheld for Privacy ehf
    Registrant Street: REDACTED FOR PRIVACY
    ...
Traceroute shows that site hosted by Hurricane Electric.

Anyone who lost money in this should sue Namecheap and Hurricane Electric. They will be stumbling all over themselves to tell your lawyers who their customer was, to avoid liability.

I don't even have a Coinbase account.

Re: Coinbase Breach Notification

#189
post #174

Earlier quoted context omitted.

Do you need me to hold your hand when we cross the street?

I'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go. Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target. One of the main functions of government is private wealth protection. Banks are a feature, not a bug.

How do you move $500K to another country? My country of origin goes apeshit when I send my parents $2000.

Re: Coinbase Breach Notification

#190

Earlier quoted context omitted.

Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

In Europe all banks are using 2FA, and it's usually based on TOTP (and enrolling the first phone is a pain usually requiring QR codes and whatnot). 17 years ago some were using smartcards as 2FA. It's doable and secure, to the point that identity theft is almost unheard of (and usually used more as a synonym of catfishing than in the American sense).

SMS is handy but it should be a last resort rather than the main second factor.

Post reply on HN