Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

271–280 of 287 posts

Re: Coinbase Breach Notification

#271

Earlier quoted context omitted.

How do you move $500K to another country? My country of origin goes apeshit when I send my parents $2000.

China will go apeshit if you try to use Bitcoin to move $500k to another country. Transferring 500k between most developed countries should be easy enough, I'd probably talk to both banks first for such a large amount.

> I'd probably talk to both banks first for such a large amount

I don't need to ask anyone to move bitcoins.

Re: Coinbase Breach Notification

#272
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

Big difference! I have personal experience of Coinbase emailing me (in writing!) that I’d get a bank overdraft fee refunded from their system-wide mistake of double-charging cryptocurrency orders. This happened right before their IPO.

Long story short, I was never refunded despite raising two support tickets. :(

Re: Coinbase Breach Notification

#273

Earlier quoted context omitted.

You can't act as an "automated market maker" in traditional finance, I'll give you that (to pick one example of something possible in DeFi). What I really mean is what can do you in DeFi that is connected with the real world? In other words, what can you do other that doesn't fall into the category of using your money to make more money with no effect on the material world? Examples of things that traditional finance…

> Examples of things that traditional finance enables that connect to the real world: An end goal of crypto is to have all financial and ownership services exist on-chain. To conceptualize the real world as somehow forever separate is going to lead to the correct conclusion that DeFi doesn't seem to affect "the real world". > - Get a student loan (you get an education) Requires identification. > - Get a car loan (you…

> An end goal of crypto is to have all financial and ownership services exist on-chain. To conceptualize the real world as somehow forever separate is going to lead to the correct conclusion that DeFi doesn't seem to affect "the real world".

I get this, and I definitely am not suggesting the real world is forever separate. I am somewhat suggesting it currently is though.

> There are cryptos looking to tokenize and fractionalize public/private equities.

Yes, but the ones I'm aware of are entirely doing it on the backs of traditional finance equities.

> Requires identification.

This is a good point and I almost explicitly called it out myself - traditional finance is valuable much because it acknowledges the existence of the individual in society, not as an abstract entity with cash flows.

Solving the identification problem is a goldmine for society at large, not just DeFi. I just find it hard to imagine a suitable solution that doesn't involve trust in the government and other institutions.

I want to make it clear that I am not anti-crypto/DeFi. I think most payment will one day be distributed/trustless at its lowest layer. But I also think that true value (in the "real world") will come when all of the trust built into the rest of society is layered on top.

Re: Coinbase Breach Notification

#274
post #256

These platforms should not offer 2fa with SMS. And force their customers to use 2FA via MFA instead.

Don't assume they don't. Most platforms not only enable multiple forms of security, you even get rewards if you choose better security. I use an exchange the uses double security, meaning you have 20 seconds to verify via email and 2FA, and on top of that the logins, withdrawals and transfers all have sperate passwords..and your able to rate limit them based on time periods. Most of the knew jerk reactions in here re…

> you even get rewards if you choose better security

Service providers should know better than their users and make the best choices for them.

It is not like when you buy a car you get to choose whether you want airbags or not. They decided for you, and you must have airbags, period.

Users, on overage, do not posses the knowledge to make the best decision when it comes to security.

They go with the least friction solution. SMS works great everybody know how they work.

So, yeah, the burden and responsibility should not be on the end user. This is clearly companies' fault.

Re: Coinbase Breach Notification

#275
post #128

Earlier quoted context omitted.

You are mistaken. A SIM swap is a compromise at the carrier, not the handset.

Ah so how is this Coinbases fault I also dont understand? Seems like a carrier issue.

Coinbase shouldn't have been using SMS as 2FA to begin with.

They also had a security bug in their SMS-based recovery system, according to other commenters in the thread.

Re: Coinbase Breach Notification

#276

Earlier quoted context omitted.

China will go apeshit if you try to use Bitcoin to move $500k to another country. Transferring 500k between most developed countries should be easy enough, I'd probably talk to both banks first for such a large amount.

> I'd probably talk to both banks first for such a large amount I don't need to ask anyone to move bitcoins.

You need to ask someone (provide ID, KYC probably) to convert them into a currency you can spend widely though.

Re: Coinbase Breach Notification

#277

Earlier quoted context omitted.

And when they do and I do, I have a large cache of weapons and ammunition to wave at them with. If you think the government is protecting your wealth, you're incredibly naive.

So you have to be strapped whenever you want to visit Starbucks? No thanks.

Funny enough with Bitcoin you have done 90% of the mugger/robber's job for them by holding the money in a criminal-friendly format.

Re: Coinbase Breach Notification

#278

Earlier quoted context omitted.

There are hybrid systems which offer the best of both worlds. For example, the open source Muun wallet uses a 2-of-2 key system[0] in which Muun only has access to one of the two keys so, unlike a traditional bank or a custodial exchange like Coinbase, they can't spend any funds without your signature. Your Muun wallet app also only has one key, so authentication with the Muun service is necessary to complete transac…

That backup defeats the 2 of 2 multi-sig, though. Users really still are their own bank in this model. If their backup is stolen, the thief can empty their wallet. It’s just not kept online. Not much different from using a hardware wallet in that respect.

> That backup defeats the 2 of 2 multi-sig, though. Users really still are their own bank in this model.

As I said, it's a hybrid—so it has some elements of "being your own bank" as well as elements of a custodial system. The point of the multi-sig model is to allow the wallet to be used for day-to-day transactions like a "hot" wallet or a custodial exchange without the risk of carrying the complete keys everywhere on an Internet-connected device and without giving up control over the funds. The backup and the 2-of-2 multi-sig each serve important functions; neither "defeats" the other.

> If their backup is stolen, the thief can empty their wallet.

And no one ever has their traditional bank account emptied due to poor password hygiene or a vulnerability in the bank's 2FA system? Transferring custody to a third party doesn't mean you can stop worrying about security. If you don't have something equivalent to this offline backup then it's true that there is one less way for a thief to gain access to the account, but then you risk being unable to prove that you are the authorized owner of the account and losing your funds that way.

> Not much different from using a hardware wallet in that respect.

Hardware wallets have a different set of trade-offs. Personally I don't like to carry mine around with me like a ordinary wallet (or my phone) for use in daily payments. It's probably secure enough that I could do that safely, but there's always the risk of losing it, and for small, everyday payments it's just not as convenient as using an app on your phone. Also, Muun works with the Lightning network, which requires an online component; I'm not aware of any hardware wallets which can fill that role.

Re: Coinbase Breach Notification

#279

Earlier quoted context omitted.

> I'd probably talk to both banks first for such a large amount I don't need to ask anyone to move bitcoins.

You need to ask someone (provide ID, KYC probably) to convert them into a currency you can spend widely though.

The ultimate goal is to make such conversions unnecessary.

Re: Coinbase Breach Notification

#280

Earlier quoted context omitted.

> I'd probably talk to both banks first for such a large amount I don't need to ask anyone to move bitcoins.

You need to ask someone (provide ID, KYC probably) to convert them into a currency you can spend widely though.

Not if you're moving to El Salvador!
Post reply on HN