Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

191–200 of 287 posts

Re: Coinbase Breach Notification

#191
post #182

Earlier quoted context omitted.

Telcos have no responsibility to stop SIM fraud. Telcos have communicated the last 30 years SMS is not secure (travels as plain text) and should not be used for 2FA. If companies have ignored this advise then it is on them.

SIM swapping also allows you to intercept voice calls, which are encrypted and supposed to be secure. The idea that telcos have no responsibility to stop people from taking over the telephone number that customers pay for is completely absurd. Moreover, often the SIM swapping is done by employees of the Telco itself using company infrastructure.

No you are not correct. The whole underlying mobile phone network infrastructure is based on (failed) trust and is not secure. Though it is slowly being replaced.

https://www.theguardian.com/technology/2016/apr/19/ss7-hack-...

https://www.firstpoint-mg.com/blog/ss7-attack-guide/

Re: Coinbase Breach Notification

#192

Earlier quoted context omitted.

Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

A decent point. It scares me to imagine all the security checks that would be required to make SMS actually secure against these kind of attacks, and then getting everyone to actually follow them.

Re: Coinbase Breach Notification

#193

Earlier quoted context omitted.

The attackers also needed to know the user's phone number and have access to their email account. That is a sufficiently high bar that I can still be sympathetic to Coinbase here. Not sure why you discount username and phone either. Each of these is an additional layer of security simply by being more information an attacker needs to collect and associate. Coinbase doesn't publish a list of usernames. And how would s…

You can easily check databases on and off the darknet to find people's phone numbers and most people don't have multiple phone numbers and rarely change their number because of the associated hassle with moving accounts. The same goes for their email and even passwords if they reused them.

For example https://truepeoplesearch.com will give you name, address, and phone number for free and it is searchable.

It’s unfortunate how much is out there.

Re: Coinbase Breach Notification

#194
post #174

Earlier quoted context omitted.

I'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go. Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target. One of the main functions of government is private wealth protection. Banks are a feature, not a bug.

And when they do and I do, I have a large cache of weapons and ammunition to wave at them with. If you think the government is protecting your wealth, you're incredibly naive.

So you have to be strapped whenever you want to visit Starbucks? No thanks.

Re: Coinbase Breach Notification

#195

Earlier quoted context omitted.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

In Europe all banks are using 2FA, and it's usually based on TOTP (and enrolling the first phone is a pain usually requiring QR codes and whatnot). 17 years ago some were using smartcards as 2FA. It's doable and secure, to the point that identity theft is almost unheard of (and usually used more as a synonym of catfishing than in the American sense). SMS is handy but it should be a last resort rather than the main se…

If you can use sms as a factor, you can use sms as a factor. The only way to win is not to play at all

Re: Coinbase Breach Notification

#196

Earlier quoted context omitted.

Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?

Re: Coinbase Breach Notification

#197

Earlier quoted context omitted.

This isn't really true. Google Voice numbers are managed by bandwidth.com and have been taken by attackers submitting fraudulent number portability requests in the past.

Don't you have to login to your Google account to port a number?

It has been possible in some instances for an attacker to port a number directly from the underlying carrier, in this case, bandwidth.com.

When I saw this happen, Google was not aware the number was gone, so calls and texts from other Google Voice users still worked.

Re: Coinbase Breach Notification

#198

Earlier quoted context omitted.

And when they do and I do, I have a large cache of weapons and ammunition to wave at them with. If you think the government is protecting your wealth, you're incredibly naive.

So you have to be strapped whenever you want to visit Starbucks? No thanks.

Lol no. Technically I can be because I'm in an open carry state but I only do that if I'm out in the wild or traveling solo late at night.

Re: Coinbase Breach Notification

#199

Earlier quoted context omitted.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service. Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported. Eventually, the end state desired will be reached (re…

So if its value is in it not being regulated and you think governments will catch up, you're saying that it will eventually become worthless.

If so, I agree. I'm just surprised to see it stated so baldly.

Re: Coinbase Breach Notification

#200
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

Many cryptocurrencies are deflationary and/or have fixed supply; I cannot say the same for the dollars in my bank account. https://fred.stlouisfed.org/series/MABMM301USM189S

Bitcoin's near infinite divisibility weakens the fixed supply argument, does it not?

The smallest possible fraction of a dollar is $0.01. You can transact BTC in denominations with a lot more zeros behind the decimal point.

Post reply on HN