Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

311–320 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#311

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Why do you see this as the fault of Coinbase? Do other companies somehow have employees that are immune to bribes and blackmail? This is due to US Government KYC laws that forced Coinbase to associate government identification with all accounts. No crypto company required ID until they were forced to.

The US Government didn't provide high-volume, bulk access to this extremely sensitive information to contractors in foreign countries with no controls over their ability to mass-exfiltrate the data.

Coinbase is the entity that set up this dangerous system.

Coinbase did it because it was cheap for them, not because they were being trustworthy custodians of information that put their customers at risk.

Sure, yes, obviously every company's employees and contractors are vulnerable to bribes and blackmail. That's why a trustworthy, competent custodian would establish systems and controls to prevent bribed and blackmailed insiders from mass-exfiltrating information that could get their customers killed.

The fact that other companies manage to be trustworthy, competent custodians while Coinbase doesn't is not the fault of KYC.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#312
post #95

Earlier quoted context omitted.

You seem to believe that AML/KYC regulation exists to benefit customers or to prevent or recover from account compromises. It does not, and I have no idea why you would think it does. Something like a Yubikey or iris-scanning stations could help to prevent Coinbase account compromises, but AML/KYC regulations do not require or even encourage them, though perhaps someday they will.

You... want to replace KYC with iris scanning stations ?

It has real drawbacks, but I wasn't talking about what would be a good idea; I was talking about what would be a useful measure for preventing or recovering from account compromises. Iris scanning would be; KYC isn't.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#313

And the reason Coinbase has to keep all that sensitive stuff, much more than what would be required to identify and authenticate you, which you hope will never be stolen, is because of know your customer laws, so you can thank your government that pictures of your passport got stolen and for whatever criminals and rogue Coinbase employees do with that info.

> And the reason Coinbase has to keep all that sensitive stuff, much more than what would be required to identify and authenticate you, which you hope will never be stolen, is because of know your customer laws

Real cop out here, be honest. Why should every single agent have access to your identity documentation (which is only required for KYC) in perpetuity?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#314

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

> People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnapped for ransom. "Significant" in this case can be $10k or less. I wonder why, select a person completely at random and by median you'll get just as much from what they have sitting in their checking account. Select a nicer area for an order of magnitude more. That's not encouragemen…

The average American can't deal with a $1000 emergency.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#315
post #262

Earlier quoted context omitted.

Coinbase is identical to a bank because it holds customer funds. Your comment isn't quite the dunk you think it is. Blockchains allow money to be held anonymously without any banks involved. Centralized exchanges are just profiting on speculation and probably should be banned.

No they don’t. “Cryptocurrency” isn’t money at all. Just because you can trade it in for money, doesn’t make it so. I can also trade in my hat to the Buffalo Exchange for money. But my hat is not money.

There is no bright line separating "money" from any other type of fungible asset

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#316
post #124

So this is probably why the phishing calls have increased from ~1 per month to ~3 per week.. good to know... Wish coinbase would let me DO something about it... Maybe fresh accounts for everyone? Maybe KYC data not directly linked to accounts? There should be SOMETHING they can do because the sheer volume of people constantly harassing CB customers is nuts.

> So this is probably why the phishing calls have increased from ~1 per month to ~3 per week.

Yes and their timeline doesn't add up with what they disclosed. If you take the Coinbase narrative, they only believed this was a 'material' issue once contacted by the hackers for a $20m demand, they weren't able to put the pieces together themselves.

The phishing has been elevated for weeks, especially via text message, and their lack of internal controls for access and monitoring are clearly severely lacking.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#317

Earlier quoted context omitted.

You know how your bank asks you to verify details when you call? Without the right details the customer support people don’t get entry into the customers account details. Banks have been doing this for 30+ years..

Which is such a lame and flawed mechanism to avoid letting them access anyone's data. I mean what are you even trying to prove here? That banks care about customer's security when they can't even implement a secure 2FA which is not just an unencrypted text message “Give a man a gun and he can rob a bank, but give a man a bank, and he can rob the world.”

> I mean what are you even trying to prove here?

That there are more options than holding your hands up and arguing the company couldn't have done anything further in terms of implementing effective controls.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#318

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Why do you see this as the fault of Coinbase? Do other companies somehow have employees that are immune to bribes and blackmail? This is due to US Government KYC laws that forced Coinbase to associate government identification with all accounts. No crypto company required ID until they were forced to.

[deleted]

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#319
post #195

Earlier quoted context omitted.

I have my phone set to silence Unknown callers. What did you have setup on the Pixel before to block them?

That’s too heavy handed for me. I get valid calls that I need to answer that aren’t in my contacts. The calls they flag as potential spam and telemarketers has been 100% accurate in my experience so i wish I could just silence those

Usually you are expecting these calls tho so you can turn off that feature when you do. If said person calls often, add them to your contacts.
Post reply on HN