I'll take my chances with the banks and Nigerian Princes.
Coinbase Breach Notification
61–70 of 287 posts
Re: Coinbase Breach Notification
#62Re: Coinbase Breach Notification
#63I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.
I mean, they'll more likely just move the goalposts than be won over, but at least they're running out of things to complain about. Between this and the Coinbase card, Coinbase has already tackled the two biggest (valid) critiques of crypto that I hear.
Re: Coinbase Breach Notification
#64Earlier quoted context omitted.
I don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.
The important part is having physical access to the phone. A targeted attack against you now requires a physical element, rather than being entirely online.
Re: Coinbase Breach Notification
#65Re: Coinbase Breach Notification
#66I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…
username and phone is not security factor. password is 1FA. SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
Not sure why you discount username and phone either. Each of these is an additional layer of security simply by being more information an attacker needs to collect and associate. Coinbase doesn't publish a list of usernames. And how would someone associate phone numbers back to them?
Re: Coinbase Breach Notification
#67In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the informatio…
Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.
Re: Coinbase Breach Notification
#68Curious what the total dollar amount involved was.
Re: Coinbase Breach Notification
#69Hardware:
Re: Coinbase Breach Notification
#70I'm done with anything crypto. Daily. Bug after bug, breach after breach. I just don't see how, at any point in the future, crypto gets any more secure than, say, Microsoft Windows. There'll always be a bug, there'll always be a fix needed. And this isn't, "oh, my software crashed for an afternoon", it's potentially a good chunk of your life savings. I'll take my chances with the banks and Nigerian Princes.