Earlier quoted context omitted.
Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.
Anyone care to speculate what the flaw in their SMS recovery flow actually was? It's hard for me to think there's even a safe way to implement SMS based account recovery. They would be smarter to just turn it off.
Coinbase Breach Notification
51–60 of 287 posts
Re: Coinbase Breach Notification
#52Earlier quoted context omitted.
>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than…
> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service. Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported. Eventually, the end state desired will be reached (re…
Gold owners also use responsible custodians when they don't store the gold themselves. I think bitcoin owners do not do the same because they want to have easy access to trading and there aren’t companies that both operate trading and are either responsible custodians or make it easy to use a different custodian for storage.
Re: Coinbase Breach Notification
#53I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…
password is 1FA.
SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
Re: Coinbase Breach Notification
#54Earlier quoted context omitted.
> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?
And they would have had to do ~6000 SIM swaps? that seems like too many for a short period of time. Maybe?
However, around the time of the breach date (March - May 2021), there were a number of "B2B" services that offered a "type in any SMS number and you will get all text messages to that number," type feature intended for customer support teams to use for shared SMS access. Those systems often had privileged access to telcos and were regularly exploited by attackers to break 2FA without even a SIM swap [1]. With those tools, stealing all SMS to a number required only intent, not conversations with telco support personnel.
[0]: https://news.ycombinator.com/item?id=28720280
[1]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...
Re: Coinbase Breach Notification
#55Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.
Agree. Although I would like coinbase to move away from SMS 2fa
Re: Coinbase Breach Notification
#56I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.
I don't think you'd get FDIC money back if an attacker got into your account. The bank might cover you if they agree it was their fault, similar to Coinbase.
Re: Coinbase Breach Notification
#57I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.
Re: Coinbase Breach Notification
#58Earlier quoted context omitted.
How? Those statements seem entirely consistent and reasonable to me. They have no evidence or reason to believe that the information was stolen from Coinbase, but beyond that they don't know how attackers got it. Your car was stolen. I haven't been able to determine conclusively who did steal it or how, but I know it wasn't me.
"I know it wasn't us" is exactly the non-sequitur conclusion they were trying to walk you toward by wording their statements as they did.
Re: Coinbase Breach Notification
#59Earlier quoted context omitted.
Agree. Although I would like coinbase to move away from SMS 2fa
I don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.
Re: Coinbase Breach Notification
#60Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.
Agree. Although I would like coinbase to move away from SMS 2fa
Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.