Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

51–60 of 287 posts

Re: Coinbase Breach Notification

#51
post #28
post #16

Earlier quoted context omitted.

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.

Anyone care to speculate what the flaw in their SMS recovery flow actually was? It's hard for me to think there's even a safe way to implement SMS based account recovery. They would be smarter to just turn it off.

SMS is fundamentally insecure, yes. But this sounds like a problem in the webapp that prepares and sends SMS messages, not SMS itself.

Re: Coinbase Breach Notification

#52

Earlier quoted context omitted.

>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…

> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service. Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported. Eventually, the end state desired will be reached (re…

Bitcoin is a self custody asset just like gold, and IMHO that and it's de-centralized exchange is actually where all the value comes from if it has any. People do own gold and store it on their own property as well.

Gold owners also use responsible custodians when they don't store the gold themselves. I think bitcoin owners do not do the same because they want to have easy access to trading and there aren’t companies that both operate trading and are either responsible custodians or make it easy to use a different custodian for storage.

Re: Coinbase Breach Notification

#53

I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…

username and phone is not security factor.

password is 1FA.

SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.

Re: Coinbase Breach Notification

#54
post #49
post #10

Earlier quoted context omitted.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

And they would have had to do ~6000 SIM swaps? that seems like too many for a short period of time. Maybe?

There is some speculation in another comment that their SMS verification server may have actually had a technical flaw, and the issue was not a lack of separate identity verification on SMS [0].

However, around the time of the breach date (March - May 2021), there were a number of "B2B" services that offered a "type in any SMS number and you will get all text messages to that number," type feature intended for customer support teams to use for shared SMS access. Those systems often had privileged access to telcos and were regularly exploited by attackers to break 2FA without even a SIM swap [1]. With those tools, stealing all SMS to a number required only intent, not conversations with telco support personnel.

[0]: https://news.ycombinator.com/item?id=28720280

[1]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...

Re: Coinbase Breach Notification

#55
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Agree. Although I would like coinbase to move away from SMS 2fa

I don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.

Re: Coinbase Breach Notification

#56
post #33

I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

FDIC insures your account against bank's overall business collapse. It doesn't insure your personal account against bank robbery of your sepcific account (deceptively named "identity theft").

I don't think you'd get FDIC money back if an attacker got into your account. The bank might cover you if they agree it was their fault, similar to Coinbase.

Re: Coinbase Breach Notification

#57
post #33

I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

There is a difference between self insured and government insured. At the end of the day I prefer self or market insured so the business itself is on the hook for a breach.

Re: Coinbase Breach Notification

#58

Earlier quoted context omitted.

How? Those statements seem entirely consistent and reasonable to me. They have no evidence or reason to believe that the information was stolen from Coinbase, but beyond that they don't know how attackers got it. Your car was stolen. I haven't been able to determine conclusively who did steal it or how, but I know it wasn't me.

"I know it wasn't us" is exactly the non-sequitur conclusion they were trying to walk you toward by wording their statements as they did.

How else would you even word it? They accurately described the situation. If people are leaping to "I know it wasn't us" then that's their own misinterpretation.

Re: Coinbase Breach Notification

#59

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

I don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.

The important part is having physical access to the phone. A targeted attack against you now requires a physical element, rather than being entirely online.

Re: Coinbase Breach Notification

#60
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse.

Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

Post reply on HN