Live data from Hacker News

Coinbase: Responding to Firefox 0-days in the wild

blog.coinbase.com

61–70 of 97 posts

Re: Coinbase: Responding to Firefox 0-days in the wild

#61
post #10

Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

The trouble is finding someone to bribe who won’t suddenly start buying new things.

the problem is finding security pundits that know that crime can force people to do things in other ways than money...

Re: Coinbase: Responding to Firefox 0-days in the wild

#62
post #10

Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

The trouble is finding someone to bribe who won’t suddenly start buying new things.

The bribe is so that you are now a party to the crime and less likely to try and turn them in after the fact. The threats to your life and the lives of your family is actually what gets the job done.

Re: Coinbase: Responding to Firefox 0-days in the wild

#63

Earlier quoted context omitted.

"We didn't literally start out with trading cards."

That's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.

I don't hold MtGox's origins against them (plus I'm a MtG fan).

But Nintendo didn't pivot from playing cards to guarded stagecoaches, they stayed in the entertainment focus and evolved over a century into electronics. The stakes were always low.

Re: Coinbase: Responding to Firefox 0-days in the wild

#64
I find this info is interesting

> The attackers went through a qualification process and multiple rounds of emails with potential victims, making sure they were high-payoff targets before they directed victims to the page containing the exploit payload.

It's a well-prepared plan combining social engineering and technical exploits

Re: Coinbase: Responding to Firefox 0-days in the wild

#65
post #50

Earlier quoted context omitted.

BCH is and will be mined proportionately to its price; since its price is far lower than BTC it also has far lower security.

OK, but I would've guessed that the reward for hijacking BCH's blockchain would be proportionally lower. And please keep in mind the context of my first comment: I was replying to the assertion that the mere fact that Coinbase continues to let its customers trade in BCH is evidence that Coinbase is run by idiots.

The thing with those silly altcoints is that there really isn't much market liquidity. Even if you were able to steal a large number of them, any attempt to convert them into something useful (i.e. dollars) with crash the price.

Re: Coinbase: Responding to Firefox 0-days in the wild

#66
post #17

Those attacks would not work if they did not enable JavaScript on every website by default.

Those attacks would not work if everyone stopped using computers.

I keep JS off by default* and it's teriffic. Using a browser with it enabled is tedious, slow and distracting in addition to the obvious heka-less-secure.

* http://surf.suckless.org/

Re: Coinbase: Responding to Firefox 0-days in the wild

#67
post #59

Earlier quoted context omitted.

Much of this is because of forks - since they offered Bitcoin before the BCH fork (and presumably ETH before the ETC fork), all of their customers who owned one of these before the fork also own the new currency. So they have to support custody for the currencies anyway (unless they want to deal with angry customers saying "What happened to my BCH! Rightfully I own it"), and if they don't support trading they'll get…

That doesn't explain the favoritism for BCH over the multitude of other forks (some worth $50-$100 per token) though. Why no Bitcoin Gold listing?

Sure enough, there are angry customers accusing Coinbase of stealing their Bitcoin Gold:

https://www.reddit.com/r/CoinBase/comments/7jtlgz/coinbase_s...

IIRC BCH and ETC forked before BTG. They probably did two of them and then asked themselves "Why are we doing this again?"

Re: Coinbase: Responding to Firefox 0-days in the wild

#69
post #20

Earlier quoted context omitted.

To follow through on that though, what makes you think that would be anything noticeable? Suddenly a coinbase employee buys a cool car or other new toy... So what? Nobody would think that was exceptional.

I think this is why investigations require low levels of evidence to start, but high levels of evidence to end. Just because it isn’t exceptional doesn’t mean that it isn’t worth looking into. People who are greedy are impulsive and are unlikely to hide an inflow of cash.

I read this as putting people's behaviors under scrutiny because "just in case". You could use your reasoning to expand the surveillance state, etc. I cannot say I like the idea.

Re: Coinbase: Responding to Firefox 0-days in the wild

#70

Earlier quoted context omitted.

> A criminal gang operating in India kidnapped and tortured cryptocurrency traders in recent weeks before demanding 80 bitcoins as ransom, police say. Three men had been held captive for 15 days inside a high-rise building and were beaten or tortured... Not even their family members were aware of the abduction. The victims had lost all hope because they had no access to anyone https://www.newsweek.com/cryptocurrency-…

Im confused why this is a response to the parent.

It's the same argument as this xkcd: https://xkcd.com/538/

Though granted it confuses keys for passwords.

Post reply on HN