Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

41–50 of 287 posts

Re: Coinbase Breach Notification

#41

Why does this say “Submitted Breach Notification Sample ” and “Sample of Notice?” How do we know the sample is real?

Because it's a sample of what the communication each customer got looks like (with e.g. a placeholder for the customer name)

Re: Coinbase Breach Notification

#42
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

Many cryptocurrencies are deflationary and/or have fixed supply; I cannot say the same for the dollars in my bank account.

https://fred.stlouisfed.org/series/MABMM301USM189S

Re: Coinbase Breach Notification

#44

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

How? Those statements seem entirely consistent and reasonable to me. They have no evidence or reason to believe that the information was stolen from Coinbase, but beyond that they don't know how attackers got it. Your car was stolen. I haven't been able to determine conclusively who did steal it or how, but I know it wasn't me.

"I know it wasn't us" is exactly the non-sequitur conclusion they were trying to walk you toward by wording their statements as they did.

Re: Coinbase Breach Notification

#45
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back.

Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap their decentralized currency inside of a centralized system (exchanges, custodianship, IRAs, etc.) for the benefits that having a bank-like organization can provide.

Re: Coinbase Breach Notification

#46
post #29

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

Phishing or malware would be obvious avenues for someone to gain this information not from Coinbase itself. If people reused passwords, they also could potentially have cobbled together 6000 valid username/password/phone combinations from previous hacks of other services.

As the Holy Writ says: https://xkcd.com/2176/

Re: Coinbase Breach Notification

#47
post #5

What can be said that has not already? It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork" Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police. Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your mil…

Coinbase is not an unregulated free-for-all. They are licensed in all 50 states, and is registered as an MSB with FinCEN. https://www.coinbase.com/legal/licenses

MSB licenses mean basically nothing. Money transmitters are borderline unregulated, certainly depending on which state they obtained their licensing.

They were actually created as a much lighter weight framework to avoid the onerous regulation of an actual depository institution.

Re: Coinbase Breach Notification

#48
post #16
post #8

In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the informatio…

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.

> everyone should walk happy.

The reimbursement comes from somewhere. Investors may not be happy. "everything is securities fraud"

https://www.google.com/search?q=%22everything+is+securities+...

Re: Coinbase Breach Notification

#49
post #10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

And they would have had to do ~6000 SIM swaps? that seems like too many for a short period of time. Maybe?

Re: Coinbase Breach Notification

#50
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Agree. Although I would like coinbase to move away from SMS 2fa
Post reply on HN