Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

521–530 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#521

Earlier quoted context omitted.

That's not what it was designed for, that's just a mixture of propaganda and confusion. It was designed to solve the double-spending problem with digital currencies, replacing the need for "a authoritative ledger" with a one difficult to forge. The political project around this was to provide people with a deflationary currency akin to gold, whose inflation could not be controlled by government. The lack of governmen…

It was designed to avoid the need for existing financial institutions. The doublespend problem was merely the blocker that prevented people from otherwise doing it. > A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution.

That's not anarchy though, that's paypal c. yr 2000

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#522
post #506

Earlier quoted context omitted.

It's worked before; Arthur Andersen ceased to exist after the Enron accounting scandal.

They just morphed into Accenture.

Actually the split between Arthur Andersen and Andersen Consulting (which later became Accenture) happened years before the Enron thing.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#523

Earlier quoted context omitted.

It’s not that it got worse, this feature has just never been great. It just feels half baked , which I agree a lot of Apple software has been trending towards. That said, what has increased is the volume of spam calls. So the importance of this feature has also increased. It’s sad because this seems like such a low hanging fruit for a big improvement. At some point in the relatively recent past, they added the indica…

>some engineer actually decided No sane person would flaunt Apple secrecy in such a fashion whilst employed there. >instead of his work quietly improving everyone’s experiBence Laughable that you feel that Apple engineers have the capacity for this kind of desire in 2025. If they did, Xcode would be way better to use. They cant even quietly improve their own experience.

Whatever man, I'm not trying to shit on them like you want me to. I think adding this simple feature that is likely little more than a line or two of code is a night an day comparison to overhauling something like Xcode to meet your definition of what "better" means

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#524
post #466

Earlier quoted context omitted.

Companies should seriously consider implementing GDPR even in the US, it certainly made taking data dumps of customer data a lot harder and certainly private images like Government IDs were encrypted on disk. I’m surprised at the lack of security if I’m honest, at Yahoo! almost nobody had access to prod user data. Essentially you cannot trust Coinbase IMO, might move the few hundred dollars of BTC out of there :-)

How would GDPR help in this case where the employees were bribed?

Internal segregation. If inplemented properly perhaps these specic employees wouldnt have access to all that data in the first place.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#525
post #346

Earlier quoted context omitted.

There are very good reasons for KYC, the problem here is not the government regulation, it's once again private companies being sloppy with their customer's data because sloppy is cheap and it's not their info on the line, it's yours, so there's little motivation for them to safeguard it _unless_ they're compelled to do it by law.

This is costing Coinbase $400M. They are well incentivized to prevent this.

In formal logic we would call this kind of argument a "post hoc justification". Any company who does anything payments-related is going to be primarily motivated to allow the most amount of transactions possible (including risky ones), everything else is a secondary consideration (including data security). I mean think about it, even if your company has a data breech, it's primarily brand reputation that's on the line, at that point your money has already been made. Of course, now that damage has been done there is a motivation to prevent it from happening in the future, but for companies like Coinbase who operate in emerging markets with little regulatory oversight, it's extremely hard to argue that they have are motivated to do anything besides grow and make money. After all, the mantra has always been "move fast and break things".

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#526
post #507

Earlier quoted context omitted.

“Hey, cryptocurrency exchange, I, a random rich person, would like to, having never interacted with you before, buy a million dollars of bitcoin and transfer it out. Today, please.” That is simply not going to happen.

Eh, million dollars would not raise a single eyebrow from an exchange side. Your bank, maybe, will have some questions about the transaction, but the things they can do to prevent you spending your money are thankfully fairly limited.

My experience with banks in UK / EU is that they will bother you for much smaller amounts than 1M. I had banks bother me for 10k transfers and other banks completely ignore me for 100k transfers.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#527

Earlier quoted context omitted.

Hence why cryptocurrency would never replace regular banks for regular people. The situation with scams and thefts has only gotten worse. Not your keys, not your coin.

I definitely cannot imagine my grandma making use of crypto, or PayPal, or her bank's online site. :)

LOL. Point taken.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#528

Earlier quoted context omitted.

If you had any significant assets on Coinbase at any time prior to this breach, spear phishing is the least of your worries. Coinbase not only leaked your full name and address, they also gave up your balances, your transaction history, and images of your government identification. People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnappe…

Companies should seriously consider implementing GDPR even in the US, it certainly made taking data dumps of customer data a lot harder and certainly private images like Government IDs were encrypted on disk. I’m surprised at the lack of security if I’m honest, at Yahoo! almost nobody had access to prod user data. Essentially you cannot trust Coinbase IMO, might move the few hundred dollars of BTC out of there :-)

> How does Coinbase protect data in transit and data at rest?

> Coinbase employs a range of technical and organizational measures to defeat efforts to intercept, surveil, or otherwise access without authorization data in transit. For instance, Coinbase encrypts all confidential data transfers to prevent interception or tampering of that data by unauthorized third parties.

Coinbase does business in the EU and thus, already has to comply with the GDPR. Moreover, the US also requires safeguards for sensitive customer information by financial services companies.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#529
post #507

Earlier quoted context omitted.

Eh, million dollars would not raise a single eyebrow from an exchange side. Your bank, maybe, will have some questions about the transaction, but the things they can do to prevent you spending your money are thankfully fairly limited.

How long do you think it takes to create an account, get your KYC documents verified, get your trading and withdrawal limits raised to a million or more, transfer funds from your brokerage account, buy tokens and then re-verify when you try to transfer the tokens out of the exchange? You'd be lucky to complete this in less than a week.

It takes about 3 days on kraken. Much less than a week.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#530

Earlier quoted context omitted.

> People with "significant" crypto balances are being assaulted on the street and in their own homes, and family members are being kidnapped for ransom. "Significant" in this case can be $10k or less. I wonder why, select a person completely at random and by median you'll get just as much from what they have sitting in their checking account. Select a nicer area for an order of magnitude more. That's not encouragemen…

The average American can't deal with a $1000 emergency.

Maybe they wouldn't be able to cover other planned expenses with said loss or something but the median (I intentionally avoid referring to "average" for reasons also mentioned in this article) amount American have access to in their transactional bank accounts is $8,000 according to the Federal Reserve: https://www.fool.com/money/research/average-savings-account-...

Someone else made a great mention though: Coinbase didn't just serve the US. For the vast majority of countries these amounts are more than the yearly disposable income of a typical household. From that angle the numbers in the stories make a bit more sense.

Post reply on HN