Earlier quoted context omitted.
Agree. Although I would like coinbase to move away from SMS 2fa
They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.
Coinbase Breach Notification
201–210 of 287 posts
Re: Coinbase Breach Notification
#202Earlier quoted context omitted.
They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.
How about allowing users to turn off sms.
Re: Coinbase Breach Notification
#203Reminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://www.ledger.com/
I must be missing something, but can someone explain what's the point of a hardware wallet? Why not just use a password manager? Hardware wallets seem to have so many downsides, as far as I can understand. You can keep multiple copies of your password manager's database (something like a kbdx file), but you won't have multiple copies of the hardware wallet. Therefore a single point of failure. If the wallet is stolen…
This is incorrect. Hardware wallets typically come with a recovery seed. Even if the original device gets destroyed, the seed helps you to get access to your addresses/crypto. This covers against all of the scenarios you mentioned.
For example, I just updated the firmware on my device this afternoon. Before I did it, I'm double-prompted to make sure I have my recovery seed in case the update fails.
As for storing in a password manager, you certainly could. I used to print my wallets out back in the day. The hardware just makes the process a bit easier and makes mistakes on my part less likely.
Re: Coinbase Breach Notification
#204Earlier quoted context omitted.
This isn't really true. Google Voice numbers are managed by bandwidth.com and have been taken by attackers submitting fraudulent number portability requests in the past.
Don't you have to login to your Google account to port a number?
https://arstechnica.com/information-technology/2021/03/16-at...
Re: Coinbase Breach Notification
#205Earlier quoted context omitted.
Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…
So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?
Re: Coinbase Breach Notification
#206Earlier quoted context omitted.
Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.
Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…
Re: Coinbase Breach Notification
#207Re: Coinbase Breach Notification
#208Earlier quoted context omitted.
Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…
So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?
Re: Coinbase Breach Notification
#209Earlier quoted context omitted.
SIM swapping also allows you to intercept voice calls, which are encrypted and supposed to be secure. The idea that telcos have no responsibility to stop people from taking over the telephone number that customers pay for is completely absurd. Moreover, often the SIM swapping is done by employees of the Telco itself using company infrastructure.
No you are not correct. The whole underlying mobile phone network infrastructure is based on (failed) trust and is not secure. Though it is slowly being replaced. https://www.theguardian.com/technology/2016/apr/19/ss7-hack-... https://www.firstpoint-mg.com/blog/ss7-attack-guide/
Re: Coinbase Breach Notification
#210Use yubikeys. Use coinbase vaults.