Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

251–260 of 287 posts

Re: Coinbase Breach Notification

#251
post #247
post #182

Earlier quoted context omitted.

SIM swapping also allows you to intercept voice calls, which are encrypted and supposed to be secure. The idea that telcos have no responsibility to stop people from taking over the telephone number that customers pay for is completely absurd. Moreover, often the SIM swapping is done by employees of the Telco itself using company infrastructure.

The incumbent telcos would love a regulatory framework where they must store address info and other personal data of their clients: Clients would then be much less likely to switch. International tourists will also be less likely to get a local SIM card and then pay exorbitant roaming charges. (Here in South Africa, clients must provide proof of their residential address. Some telcos even insist on verifying the thum…

Don't see how that's relevant to the thread at hand. The problem here is that the Telco has an existing paying customer for a number, and has systems that allow other malicious actors to take over that number instead. It's not about verifying the absolute identity of the account owner, they only need to verify that the new SIM using a number has permission from the person who rightfully owns the account. In many cases, this fraud is being committed by employees of the carrier (e.g. at it's retail locations). That means the carrier clearly doesn't have adequate controls to prevent abuse.

Re: Coinbase Breach Notification

#252

Earlier quoted context omitted.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

So to sum up, an organization promising to take people's money and keep it safe can't afford to do it except for people with a great deal of money. However, they're still going to accept smaller amounts of money. Did I get that right?

Depends on how you define "keep it safe". If I give you $100 to keep safe, I don't care how many times you get robbed as long as I get $100 back when I want it. If I can get my money, it's safe.

Re: Coinbase Breach Notification

#253

Earlier quoted context omitted.

Coinbase and other sites (especially those that deal in money) should stop using SIM cards as a form of authentication. While carriers should probably do more to secure SIMs and phone #s, it has always been known that the system was never designed to be used as a security mechanism, and Coinbase using it as such is a security flaw that they are responsible for.

Okta architect here. It's hard enough getting MFA to work in a large organization where technically illiterate people are surrounded by coworkers to ask who have all figured out their RSA tokens or Okta Verify enrollment. Trying to manage this for the general public would be an incredible undertaking. The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforc…

I feel I should clarify, I do not work for Okta, but play the role of Okta architect on TV.

Re: Coinbase Breach Notification

#254

Earlier quoted context omitted.

Does that help? You cannot walk into a bank and ask to put your money to work in the same way that they are already putting your money to work just by holding it in an account with them. At least, not for average people.

You can't act as an "automated market maker" in traditional finance, I'll give you that (to pick one example of something possible in DeFi). What I really mean is what can do you in DeFi that is connected with the real world? In other words, what can you do other that doesn't fall into the category of using your money to make more money with no effect on the material world? Examples of things that traditional finance…

> Examples of things that traditional finance enables that connect to the real world:

An end goal of crypto is to have all financial and ownership services exist on-chain. To conceptualize the real world as somehow forever separate is going to lead to the correct conclusion that DeFi doesn't seem to affect "the real world".

> - Get a student loan (you get an education)

Requires identification.

> - Get a car loan (you get a car)

Requires identification.

> - Get a home loan (you get a house)

Requires identification.

> - Insure your car or home (perhaps including insurance in finance is a bit broad, but I think it's appropriate)

Requires identification.

> - Have some claim on the future cash flows of a company that makes real things (public equities)

Doesn't necessarily require identification. There are cryptos looking to tokenize and fractionalize public/private equities. The equity would exist on chain, not on the private ledgers of banks/clearing houses/brokers/the NASDAQ. You would own your equity via a private key, and not by the say so of Fidelity (e.g.) and the government.

You've listed three types of loans that require you to have some form of identity which allows for the existence of credit/reputation. Until crypto has a functional decentralized identity ((which is being worked on by many)[1], and even has a (W3C draft)[2]) and government recognition, you will likely not see traditional lending products. Doesn't mean it isn't possible.

Insurance also requires identification for reputational purposes, but less for enforcing payments and more for measuring risk.

Crop insurance is a popular use case being investigated for poor rural areas to get insurance. Remember, traditional finance requires massive human capital infrastructure, general civil infrastructure, and minimized governmental corruption to ensure debt repayment occurs. It's may be easier bootstrap insurance from a decentralized network/blockchain + satellite internet, for certain communities.

[1] https://www.google.com/search?q=decentralized+identity

[2] https://www.w3.org/TR/did-core/

Re: Coinbase Breach Notification

#255
post #249

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

There's still no FDIC insurance -- and never will be. If people make a run on the BTC Bank, and your value drops by 40%, CoinBase isn't going to refund you the losses.

I don't get it. BTC is not USD

Re: Coinbase Breach Notification

#256

These platforms should not offer 2fa with SMS. And force their customers to use 2FA via MFA instead.

Don't assume they don't. Most platforms not only enable multiple forms of security, you even get rewards if you choose better security. I use an exchange the uses double security, meaning you have 20 seconds to verify via email and 2FA, and on top of that the logins, withdrawals and transfers all have sperate passwords..and your able to rate limit them based on time periods.

Most of the knew jerk reactions in here really don't see to know very much about how this actually works and how it's actually the users responsibility at the end of the day.

Re: Coinbase Breach Notification

#257
post #128

Earlier quoted context omitted.

if they did a SIM swap that means that they compromised the user's phone, if I'm not mistaken.

You are mistaken. A SIM swap is a compromise at the carrier, not the handset.

Ah so how is this Coinbases fault I also dont understand? Seems like a carrier issue.

Re: Coinbase Breach Notification

#258

Earlier quoted context omitted.

The fact that there’s no OTP option even available is what bothers me. Let the power users use OTP if they want it. When OTP is available I always remove my phone and use that. Sim swap is such a common attack these days.

Coinbase supports Google Authenticator, and also hardware keys like Yubikey. https://help.coinbase.com/en/coinbase/getting-started/verify...

Good to know! I didn’t see the option on my phone. Will set it up ASAP.

Re: Coinbase Breach Notification

#259
post #200

Earlier quoted context omitted.

Bitcoin's near infinite divisibility weakens the fixed supply argument, does it not? The smallest possible fraction of a dollar is $0.01. You can transact BTC in denominations with a lot more zeros behind the decimal point.

Read more about Bitcoin and what fixed supply means. There will only be 21 million Bitcoin ever, but the dollars keep being printed en masse. This makes each Bitcoin continually worth more and each dollar continually worth less. https://www.visualcapitalist.com/purchasing-power-of-the-u-s...

[deleted]

Re: Coinbase Breach Notification

#260
post #249

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

There's still no FDIC insurance -- and never will be. If people make a run on the BTC Bank, and your value drops by 40%, CoinBase isn't going to refund you the losses.

... ?

Fidelity isn't going to refund me losses on the stocks I purchase. What's your point?

Post reply on HN