Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

261–270 of 287 posts

Re: Coinbase Breach Notification

#261
post #155
post #146

Earlier quoted context omitted.

Coinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process". [1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...

With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special…

>As soon as Coinbase learned of this issue, we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process

How is it possible to update the SMS recover protocol to prevent sim swapping?

Re: Coinbase Breach Notification

#262

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Coinbase is reimbursing people because there was a flaw in Coinbase. If an individual's computer gets hacked and the hacker drains the user's account, I doubt Coinbase would reimburse.

Re: Coinbase Breach Notification

#263
post #168

I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…

I'm skeptical of their breach notification for the following reasons... If they were certain this was PURELY a phishing campaign against their users, then they had no need to disclose to the government. Their wording in their disclosure is very very carefully crafted to not deny a breach of their data - pending "conclusive" evidence. They made a choice to disclose so that the gov't could never claim that they failed…

This disclosure says that everyone who was hacked had their email inbox hacked. So you're saying that someone hacked Coinbase to find your email address, then once they found your address, hacked your email inbox some other way, then used that to hack Coinbase? That sounds very roundabout, although I guess not impossible. I guess it's possible Coinbase could have some info leak somewhere that would leak your email address.

Did you ever use any other cryptocurrency website? If so, one of those could have been hacked in order for the hackers to get a list of users to target.

Re: Coinbase Breach Notification

#264

The attack still goes on. Email today: Coinbase Coinbase Verify your email address In order to continue using your Coinbase account, you need to reconfirm your email address. To avoid service interruptions verify your email. Verify Email Address If you did not sign up for this account you can ignore this email and the account will be deleted. Get the latest Coinbase App for your phone Coinbase iOS mobile bitcoin wall…

I've been targeted as well, and there is no way "social media" was a source for my coinbase account details, as the coinbase statement implies. I am 90% certain Coinbase has suffered a broad breach of customer data that they have not disclosed yet.

Animats doesn't have a Coinbase account. Clearly the phisher got Animats's email from some other source than Coinbase.

https://haveibeenpwned.com/ says my data has been leaked ~25 times.

Re: Coinbase Breach Notification

#265
post #145

Earlier quoted context omitted.

What they should be doing, is to subsidise YubiKeys to their high-value customers. Not just to lock down the logins to Coinbase, but to also secure their customers' email, Twitter accounts, and as many other online systems as would support hardware backed WebAuthn. Hell, PokerStars did this with RSA tokens back in 2008 so it's not like it's a new idea.

I love my YubiKey but it doesn't work with my phone. Have newer models solved this problem?

Yes. You need NFC chipped phone and and NFC model YubiKey.

That also solves a major usability issue: instead of trying to juggle between a mobile application and a TOTP authenticator (on the same device!), or plugging in a USB adapter for authentication needs, you just quickly tap/wave your keyring next to the phone. Or take your phone quickly by your pocket when you need the second factor.

Re: Coinbase Breach Notification

#266
post #181

Earlier quoted context omitted.

The pain in the ass is why it should be used as an primary app-based 2FA recovery mechanism. Doing 2FA via app is fine for most users. The failures happen when users lose their phone and need to reset 2FA. That's where the pain in the ass (but secure pain in the ass) of U2F would come in handy, to re-enroll primary 2FA. Nobody presently has good ways of doing 2FA resets. U2F hardware is a near-perfect solution.

It's a near perfect solution assuming nobody ever loses their U2F device.

This is why you get two, one primary and one backup - they (Coinbase) actively encourage you to enroll two (or more, i think the limit is 5 or 6).

Also, their mobile app recently was updated to support NFC Yubikeys...

Re: Coinbase Breach Notification

#267

Earlier quoted context omitted.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

There are hybrid systems which offer the best of both worlds. For example, the open source Muun wallet uses a 2-of-2 key system[0] in which Muun only has access to one of the two keys so, unlike a traditional bank or a custodial exchange like Coinbase, they can't spend any funds without your signature. Your Muun wallet app also only has one key, so authentication with the Muun service is necessary to complete transac…

That backup defeats the 2 of 2 multi-sig, though. Users really still are their own bank in this model. If their backup is stolen, the thief can empty their wallet. It’s just not kept online. Not much different from using a hardware wallet in that respect.

Re: Coinbase Breach Notification

#268

I wonder how "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident" is to be read. To me, that reads as "if you had 1 BTC stolen on May 20, we will deposit 40k USD into your account, because that was the value of 1 BTC as of May 20", not "if you had 1 BTC stolen, there is now 1 BTC back in your account". The timeframe listed…

I also find that to be a weird stance. People can hold USD or stablecoin a on their Coinbase account if they wish. For people who choose to hold assets other than USD, it seems more logical to replace those assets. Coinbase already trades all of them. Or, since this was a Coinbase flaw, allow the user to choose whether they want the original assets restored or the dollar value at the time of theft (since in theory they could have sold). This way Coinbase feels more pain, but customers should be happy because they come out no worse and possibly better off.

Re: Coinbase Breach Notification

#269
post #39

Earlier quoted context omitted.

> differentiate the coins at all from regular banking Apart from the fact that you can save value over time? Because the dollar is only going down.

You can verify that one bitcoin you have today will not be diluted by more than a certain amount tomorrow. Value is based on people’s value of the object though, and I wouldn’t necessarily bet on Bitcoin keeping that over the long term.

> and I wouldn’t necessarily bet on Bitcoin keeping that over the long term.

You can however bet 100% that your dollar is going to be worth WAY less in 20 years than now.

Re: Coinbase Breach Notification

#270

Earlier quoted context omitted.

Many cryptocurrencies are deflationary and/or have fixed supply; I cannot say the same for the dollars in my bank account. https://fred.stlouisfed.org/series/MABMM301USM189S

That's why you don't store money in your bank account, you keep it in investment vehicles which also appreciate in value over the long run (not the best inflation foil, but an OK one)

Investment vehicles like the stock market are being propped up by the money printing, so I don’t consider that a good alternative. That’s just a game of musical chairs that stops and usually the poor people and those furthest from the money printer are the ones without a chair.
Post reply on HN