Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.
The trouble is finding someone to bribe who won’t suddenly start buying new things.
Coinbase: Responding to Firefox 0-days in the wild
61–70 of 97 posts
Re: Coinbase: Responding to Firefox 0-days in the wild
#62Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.
The trouble is finding someone to bribe who won’t suddenly start buying new things.
Re: Coinbase: Responding to Firefox 0-days in the wild
#63Earlier quoted context omitted.
"We didn't literally start out with trading cards."
That's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.
But Nintendo didn't pivot from playing cards to guarded stagecoaches, they stayed in the entertainment focus and evolved over a century into electronics. The stakes were always low.
Re: Coinbase: Responding to Firefox 0-days in the wild
#64> The attackers went through a qualification process and multiple rounds of emails with potential victims, making sure they were high-payoff targets before they directed victims to the page containing the exploit payload.
It's a well-prepared plan combining social engineering and technical exploits
Re: Coinbase: Responding to Firefox 0-days in the wild
#65Earlier quoted context omitted.
BCH is and will be mined proportionately to its price; since its price is far lower than BTC it also has far lower security.
OK, but I would've guessed that the reward for hijacking BCH's blockchain would be proportionally lower. And please keep in mind the context of my first comment: I was replying to the assertion that the mere fact that Coinbase continues to let its customers trade in BCH is evidence that Coinbase is run by idiots.
Re: Coinbase: Responding to Firefox 0-days in the wild
#66Those attacks would not work if they did not enable JavaScript on every website by default.
Those attacks would not work if everyone stopped using computers.
Re: Coinbase: Responding to Firefox 0-days in the wild
#67Earlier quoted context omitted.
Much of this is because of forks - since they offered Bitcoin before the BCH fork (and presumably ETH before the ETC fork), all of their customers who owned one of these before the fork also own the new currency. So they have to support custody for the currencies anyway (unless they want to deal with angry customers saying "What happened to my BCH! Rightfully I own it"), and if they don't support trading they'll get…
That doesn't explain the favoritism for BCH over the multitude of other forks (some worth $50-$100 per token) though. Why no Bitcoin Gold listing?
https://www.reddit.com/r/CoinBase/comments/7jtlgz/coinbase_s...
IIRC BCH and ETC forked before BTG. They probably did two of them and then asked themselves "Why are we doing this again?"
Re: Coinbase: Responding to Firefox 0-days in the wild
#68Does it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?
Re: Coinbase: Responding to Firefox 0-days in the wild
#69Earlier quoted context omitted.
To follow through on that though, what makes you think that would be anything noticeable? Suddenly a coinbase employee buys a cool car or other new toy... So what? Nobody would think that was exceptional.
I think this is why investigations require low levels of evidence to start, but high levels of evidence to end. Just because it isn’t exceptional doesn’t mean that it isn’t worth looking into. People who are greedy are impulsive and are unlikely to hide an inflow of cash.
Re: Coinbase: Responding to Firefox 0-days in the wild
#70Earlier quoted context omitted.
> A criminal gang operating in India kidnapped and tortured cryptocurrency traders in recent weeks before demanding 80 bitcoins as ransom, police say. Three men had been held captive for 15 days inside a high-rise building and were beaten or tortured... Not even their family members were aware of the abduction. The victims had lost all hope because they had no access to anyone https://www.newsweek.com/cryptocurrency-…
Im confused why this is a response to the parent.
Though granted it confuses keys for passwords.