Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

341–350 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#341
post #214

Earlier quoted context omitted.

There are very good reasons for KYC, the problem here is not the government regulation, it's once again private companies being sloppy with their customer's data because sloppy is cheap and it's not their info on the line, it's yours, so there's little motivation for them to safeguard it _unless_ they're compelled to do it by law.

The people who designed a government regulation to deputize private companies couldn't possibly have known how sloppy private companies are with other people's data? They could have designed KYC to minimize long-term storage requirements etc at some cost to what they could enforce, but a government like the US is inherently sloppy with the rights that are reserved for parties besides itself.

I think if I coloured it as [gov't] deputizing [companies], and prioritized financial banks not knowing their customers, in case they decide they get hacked, I could sort of get excited about blaming regulation.

At the end of the day it'd be hard for me to continue holding that because, on the balance, we expect companies to keep data private and to not enable illegal activity, not gov't to avoid asking companies to do things, lest they screw up.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#342

Earlier quoted context omitted.

How can customer support operate without knowing anything about the customer?

You know how your bank asks you to verify details when you call? Without the right details the customer support people don’t get entry into the customers account details. Banks have been doing this for 30+ years..

This also wouldn't be particularly difficult to implement.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#343

I have been receiving regular spear phishing calls from these guys, or someone who bought the leaked data, with classic tactics like claiming that I need to confirm a potentially fraudulent transaction. They speak perfect English with an American accent, sound very friendly, and have knowledge of your account balance. Thankfully on the first call I realized it was a scam right away, and Google's call screening featur…

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Companies should seriously consider implementing GDPR even in the US, it certainly made taking data dumps of customer data a lot harder and certainly private images like Government IDs were encrypted on disk. I’m surprised at the lack of security if I’m honest, at Yahoo! almost nobody had access to prod user data.

Essentially you cannot trust Coinbase IMO, might move the few hundred dollars of BTC out of there :-)

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#346

And the reason Coinbase has to keep all that sensitive stuff, much more than what would be required to identify and authenticate you, which you hope will never be stolen, is because of know your customer laws, so you can thank your government that pictures of your passport got stolen and for whatever criminals and rogue Coinbase employees do with that info.

There are very good reasons for KYC, the problem here is not the government regulation, it's once again private companies being sloppy with their customer's data because sloppy is cheap and it's not their info on the line, it's yours, so there's little motivation for them to safeguard it _unless_ they're compelled to do it by law.

This is costing Coinbase $400M. They are well incentivized to prevent this.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#347
post #315

Earlier quoted context omitted.

No they don’t. “Cryptocurrency” isn’t money at all. Just because you can trade it in for money, doesn’t make it so. I can also trade in my hat to the Buffalo Exchange for money. But my hat is not money.

There is no bright line separating "money" from any other type of fungible asset

Except for, you know, being able to spend it where you buy things? And deposit it into an actual bank? Those seem sort of intrinsic to how we use money today.

https://en.wikipedia.org/wiki/Legal_tender

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#348
post #327

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

They said less than 1% of users were affected.

probably the top 1%.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#349
post #88
post #78

Earlier quoted context omitted.

You are writing this as if you know what countries Coinbase's call centers are located in and the role of organized crime in their economies, but you don't actually know either of those things.

Lol, that's because while Coinbase emphasizes its commitment to security and compliance specific details about the geographic distribution of its offshore personnel are not disclosed in its public filings.

The fact that offshore support is allowed to access KYC information for US-based customers should be against some sort of regulation.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#350
post #336

Earlier quoted context omitted.

I just switched to iPhone from a pixel device and I’m shook by all the spam calls. How do iPhone users deal with this?

Unfortunately blocking all unknown calls is the only way to sanity. Otherwise we're talking 6-9 calls coming in ALL DAY, EVERY DAY. The calls are coming from new numbers, across multiple area codes. A few months ago I would have advised using Begone ( https://apps.apple.com/us/app/begone-spam-call-blocker/id159... ) to block but that only worked since these calls were isolated to blocks of area codes that were pretty…

I can't block all calls, but the screening feature on my Pixel did an immense job of filtering out the spam.
Post reply on HN