Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

31–40 of 287 posts

Re: Coinbase Breach Notification

#31
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

>> Coinbase made everyone whole

No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than $2,000, but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service.

Re: Coinbase Breach Notification

#32
post #23
post #12

Earlier quoted context omitted.

In the linked PDF, Coinbase does not claim to have knowledge of a vulnerability in their system (edit: though it does note "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process," I interpreted that as "we supported SMS account recovery at all" which is inherently broken [0]). The requisite two-factor bypass is detailed in the linked pdf: > Even with the information described above, addi…

They also say "we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process". What did they update if it wasn't due to a weakness on their side? EDIT: on reading some of their docs, recovery is supposed to be followed by the user submitting ID documents etc before they get full access back - maybe that's the part they didn't do before or that could somehow be circumven…

I bet that control of email address + SMS 2FA was sufficient, alone, to recover the Coinbase account password. Lots of systems permit this kind of recovery, and while I may tell a technical crowd "if you use SMS for 2FA, that's on you" less technical users may not have the requisite background to understand the security tradeoff they make in doing so.

The "flaw," in my reading of it, was to support SMS-based account recovery at all. But I'm not necessarily right here, and open to alternatives.

Re: Coinbase Breach Notification

#33
I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed).

It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

Re: Coinbase Breach Notification

#34
post #28
post #16

Earlier quoted context omitted.

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.

Anyone care to speculate what the flaw in their SMS recovery flow actually was? It's hard for me to think there's even a safe way to implement SMS based account recovery. They would be smarter to just turn it off.

I do not have specific answer for Coinbase. Typically, the flaw would be in modifying one of the form inputs to get the code delivered to a different phone number. That usually works out to either modifying the "destination number" client-side form value, or swapping in an edited/reused session token from a different login session's MFA challenge, to exploit missing ownership checks on the various underlying pkey object IDs.

Re: Coinbase Breach Notification

#35
post #10

Earlier quoted context omitted.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

It doesn't matter who techinically is at fault Coinbase wants to stay ahead of the potential bad press and people pulling all their funds from the platform. Probably just figured this was cheaper.

I'm in no way arguing that they shouldn't notify people/replace money/..., I just wonder where the confidence for the claim that it was just SIM swapping comes from.

Re: Coinbase Breach Notification

#36
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service.

Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported.

Eventually, the end state desired will be reached (regulation, customer service, insurance, pursuit of value theft, etc), it's just taking time for governments and Big Finance to catch up.

EDIT: https://www.cnbc.com/2021/10/01/defi-protocol-compound-mista... (DeFi bug accidentally gives $90 million to users, founder begs them to return it)

https://en.wikipedia.org/wiki/Cryptocurrency_and_crime

Re: Coinbase Breach Notification

#39
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

> differentiate the coins at all from regular banking

Apart from the fact that you can save value over time? Because the dollar is only going down.

Re: Coinbase Breach Notification

#40

Earlier quoted context omitted.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service. Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported. Eventually, the end state desired will be reached (re…

We already have all of those things.
Post reply on HN