Earlier quoted context omitted.
You need to ask someone (provide ID, KYC probably) to convert them into a currency you can spend widely though.
Not if you're moving to El Salvador!
Coinbase Breach Notification
281–287 of 287 posts
Re: Coinbase Breach Notification
#282Earlier quoted context omitted.
I'm skeptical of their breach notification for the following reasons... If they were certain this was PURELY a phishing campaign against their users, then they had no need to disclose to the government. Their wording in their disclosure is very very carefully crafted to not deny a breach of their data - pending "conclusive" evidence. They made a choice to disclose so that the gov't could never claim that they failed…
This disclosure says that everyone who was hacked had their email inbox hacked. So you're saying that someone hacked Coinbase to find your email address, then once they found your address, hacked your email inbox some other way, then used that to hack Coinbase? That sounds very roundabout, although I guess not impossible. I guess it's possible Coinbase could have some info leak somewhere that would leak your email ad…
The thing that might have been hacked could have easily been a CRM or email marketing system - possibly even via some 3rd party supplier.
Obviously there was no hack of the Coinbase accounting system - for the reasons you mentioned.
Re: Coinbase Breach Notification
#283Re: Coinbase Breach Notification
#284Earlier quoted context omitted.
I love my YubiKey but it doesn't work with my phone. Have newer models solved this problem?
My iPhone supports my Google Titankey through NFC, and I think newer Yubikeys also have NFC.
Please tell me how to do that?
Two iPhones and every type of Titan key that is currently sold, still haven't been able to make NFC work, nor authentication over Bluetooth.
Re: Coinbase Breach Notification
#285Earlier quoted context omitted.
With only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special…
>As soon as Coinbase learned of this issue, we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process How is it possible to update the SMS recover protocol to prevent sim swapping?
[0]: https://help.coinbase.com/en/pro/managing-my-account/account...
Re: Coinbase Breach Notification
#286Earlier quoted context omitted.
My iPhone supports my Google Titankey through NFC, and I think newer Yubikeys also have NFC.
HOLD ON. You can get your iPhone to actually recognize your Titan key via NFC? Please tell me how to do that? Two iPhones and every type of Titan key that is currently sold, still haven't been able to make NFC work, nor authentication over Bluetooth.
Re: Coinbase Breach Notification
#287Earlier quoted context omitted.
HOLD ON. You can get your iPhone to actually recognize your Titan key via NFC? Please tell me how to do that? Two iPhones and every type of Titan key that is currently sold, still haven't been able to make NFC work, nor authentication over Bluetooth.
You just tap your key to the back of your iPhone whenever prompted (such as Coinbase app login).