Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

221–230 of 287 posts

Re: Coinbase Breach Notification

#221
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach

6000 customers affected. If it wasn't a YC company you'd never say that.

Re: Coinbase Breach Notification

#222
post #69

Reminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://www.ledger.com/

I must be missing something, but can someone explain what's the point of a hardware wallet? Why not just use a password manager? Hardware wallets seem to have so many downsides, as far as I can understand. You can keep multiple copies of your password manager's database (something like a kbdx file), but you won't have multiple copies of the hardware wallet. Therefore a single point of failure. If the wallet is stolen…

Hardware wallet protocol involves a key phrase and password you keep secure elsewhere. You need either wallet + password, or if the wallet breaks, you can buy a new one and initialize it with the seed phrase and then use the same password.

You could use a multi purpose computer, e.g. a phone or PC and software to do the same, but they are more complex devices with more avenues to exploit them, e.g. a keylogger plus something than can upload your keepass file means you're robbed.

Re: Coinbase Breach Notification

#223
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

This seems like an egregious use of the word "literally" I think you should look up the use cases for decentralized finance.

In all seriousness, in what way is defi interacting with the non-defi world right now to provide value? I'm not too informed about the space, but from a distance it seems like every defi innovation so far is just building on top of something else in the defi space.

Classic answers like "banking the unbanked in third world countries" don't seem to be shaking out yet.

Re: Coinbase Breach Notification

#224
post #174

Earlier quoted context omitted.

I'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go. Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target. One of the main functions of government is private wealth protection. Banks are a feature, not a bug.

How do you move $500K to another country? My country of origin goes apeshit when I send my parents $2000.

China will go apeshit if you try to use Bitcoin to move $500k to another country.

Transferring 500k between most developed countries should be easy enough, I'd probably talk to both banks first for such a large amount.

Re: Coinbase Breach Notification

#225

Earlier quoted context omitted.

In Europe all banks are using 2FA, and it's usually based on TOTP (and enrolling the first phone is a pain usually requiring QR codes and whatnot). 17 years ago some were using smartcards as 2FA. It's doable and secure, to the point that identity theft is almost unheard of (and usually used more as a synonym of catfishing than in the American sense). SMS is handy but it should be a last resort rather than the main se…

If you can use sms as a factor, you can use sms as a factor. The only way to win is not to play at all

Yeah what I meant is that companies should propose other methods than SMS.

SMS can be good enough to confirm a password reset link that was sent by email (so you will not really do anything without access to an account's linked email address), but not as the main second factor for login.

Re: Coinbase Breach Notification

#226
post #99

Earlier quoted context omitted.

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

for many users the alternative is no 2FA at all I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

I don't have a phone that will run apps. I'm pretty sure I'm not alone.

Re: Coinbase Breach Notification

#227
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

This seems like an egregious use of the word "literally" I think you should look up the use cases for decentralized finance.

The cypherpunk crowd on HN seems to be all but gone. Overwhelmingly negative takes on anything crypto-related in favor of... big banks and media conglomerates.

Re: Coinbase Breach Notification

#228

Earlier quoted context omitted.

This seems like an egregious use of the word "literally" I think you should look up the use cases for decentralized finance.

In all seriousness, in what way is defi interacting with the non-defi world right now to provide value? I'm not too informed about the space, but from a distance it seems like every defi innovation so far is just building on top of something else in the defi space. Classic answers like "banking the unbanked in third world countries" don't seem to be shaking out yet.

To ask a different question of traditional banks - where can you do what you can do in DeFi today in traditional finance - without either being an investment bank or a HNW individual?

Re: Coinbase Breach Notification

#229
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> i.e., compromise of Coinbase's infrastructure

How is this not? 2FA is not to 2FA is you can recover your account with just a text. It does seem a bad engineering decision on their side.

Re: Coinbase Breach Notification

#230
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

If you know what DeFi is, I don't know how you can arrive at this conclusion. At this moment, you as an average person can not profit with your money in the same way that banks profit with your money. You know what the money in your checking and savings account is actually doing right now, right?
Post reply on HN