Earlier quoted context omitted.
No you are not correct. The whole underlying mobile phone network infrastructure is based on (failed) trust and is not secure. Though it is slowly being replaced. https://www.theguardian.com/technology/2016/apr/19/ss7-hack-... https://www.firstpoint-mg.com/blog/ss7-attack-guide/
replaced by a system which is similarly secure against all classes of attackers that anyone gives a crap about.
Coinbase Breach Notification
211–220 of 287 posts
Re: Coinbase Breach Notification
#212Earlier quoted context omitted.
No you are not correct. The whole underlying mobile phone network infrastructure is based on (failed) trust and is not secure. Though it is slowly being replaced. https://www.theguardian.com/technology/2016/apr/19/ss7-hack-... https://www.firstpoint-mg.com/blog/ss7-attack-guide/
replaced by a system which is similarly secure against all classes of attackers that anyone gives a crap about.
Re: Coinbase Breach Notification
#213Earlier quoted context omitted.
So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?
When I went looking for an online brokerage in the USA with a reasonable login process (i.e. 2FA, not by SMS ever ) it seemed pretty hard to find one. (Maybe that's changed?) These brokerages handle amounts much greater than a software engineer's retirement savings.
Re: Coinbase Breach Notification
#214Earlier quoted context omitted.
Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…
In Europe all banks are using 2FA, and it's usually based on TOTP (and enrolling the first phone is a pain usually requiring QR codes and whatnot). 17 years ago some were using smartcards as 2FA. It's doable and secure, to the point that identity theft is almost unheard of (and usually used more as a synonym of catfishing than in the American sense). SMS is handy but it should be a last resort rather than the main se…
Re: Coinbase Breach Notification
#215Earlier quoted context omitted.
I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…
There are hybrid systems which offer the best of both worlds. For example, the open source Muun wallet uses a 2-of-2 key system[0] in which Muun only has access to one of the two keys so, unlike a traditional bank or a custodial exchange like Coinbase, they can't spend any funds without your signature. Your Muun wallet app also only has one key, so authentication with the Muun service is necessary to complete transac…
Re: Coinbase Breach Notification
#216Earlier quoted context omitted.
When I went looking for an online brokerage in the USA with a reasonable login process (i.e. 2FA, not by SMS ever ) it seemed pretty hard to find one. (Maybe that's changed?) These brokerages handle amounts much greater than a software engineer's retirement savings.
Fidelity has the option to use OTP only (although its unfortunately a shitty Symantec app)
Re: Coinbase Breach Notification
#217Earlier quoted context omitted.
Coinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process". [1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...
With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special…
Coinbase is very clear in the breach notification that attackers had already acquired users' (a) emails, (b) passwords, and importantly (c) already have access to the users' primary email accounts. At that point, the only thing left preventing account takeover would be the 2FA challenge, and since Coinbase said there was "a flaw in Coinbase’s SMS Account Recovery process" I find it a bizarre conclusion to think that flaw was just a standard SIM-swap.
Edit: Actually, pretty positive it was not just a standard SIM-swap given that, if it were, Coinbase would not have specifically called out "a flaw in Coinbase’s SMS Account Recovery process". If it were just normal SIM-swapping bad guys would have just used that to defeat 2FA during the login process - there would have been no need for them to mess with the account recovery process. That's actually not that uncommon a bug, where 2FA works great to protect login, but there is an oversight that makes it not required during the account recovery process (by definition you're letting people into an account during the recovery process even if they're missing one of their authentication methods) that makes the whole 2FA moot.
Re: Coinbase Breach Notification
#218Earlier quoted context omitted.
So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?
When I went looking for an online brokerage in the USA with a reasonable login process (i.e. 2FA, not by SMS ever ) it seemed pretty hard to find one. (Maybe that's changed?) These brokerages handle amounts much greater than a software engineer's retirement savings.
For traditional finance, it's pretty different. E.g., "If fraudulent electronic withdrawals are made from your bank or credit union account but your ATM or debit card is not lost or stolen, you are not liable if you write to let the bank or credit union know about the error within 60 days of when they send you the account statement showing the fraudulent withdrawals." https://ovc.ojp.gov/sites/g/files/xyckuh226/files/media/docu...
Re: Coinbase Breach Notification
#219Earlier quoted context omitted.
Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.
Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…
RSA enrollment is probably the single most challenging end user issue our IT folks deal with. After password reset it’s the #2 call, and lots of time, training and engineering effort has been expended to improve the experience. (And those efforts were very effective!)
Re: Coinbase Breach Notification
#220Earlier quoted context omitted.
So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?
When I went looking for an online brokerage in the USA with a reasonable login process (i.e. 2FA, not by SMS ever ) it seemed pretty hard to find one. (Maybe that's changed?) These brokerages handle amounts much greater than a software engineer's retirement savings.
If you have a lot of money, most brokers will ship you a hardware token.