Live data from Hacker News

Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

cnbc.com

61–70 of 550 posts

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#61
post #47

Earlier quoted context omitted.

How can customer support operate without knowing anything about the customer?

A shared or hashed secret would do it. Plenty of exchanges don't know their customers, and in fact that is how they get their customers.

No. Coinbase deals with fiat money, therefore subject to AML and KYC regulations.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#63
post #59

The problem is that it seems like the data that leaked is also the data that would be used to do account recovery. And what that means is that 1) If you lose access to your account (through either your own fault, or coinbases fault) that the process of recovering it may not be so straightforward anymore. 2) Hackers can try to “recover” accounts now using this leaked info. This is a huge problem. What coinbase needs a…

> What coinbase needs are IRL offices where you can go and do things like account recovery, and where people trying to steal money can be caught and prosecuted (and makes a huge barrier for the overseas thieves who are usually doing this) That's just a bank.

Correct. Coinbase is a bank that holds cryptocurrency.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#64
post #52
post #17

The article keeps saying overseas employees or contractors, but isn't more specific on who Coinbase entrusted with this sensitive customer PII. The bottom line is Coinbase didn't adequately secure sensitive customer information, and it was leaked. Not, "Gosh, 'overseas' people, what can ya do?"

Bribes are one thing, but threats could also happen. This is a big part of the reason why I absolutely hate entities that think residential addresses should be public record. This is a precedent to Coinbase employees getting physical threats at their door just because e.g. some voter registration, utility company, bank, credit card, or court record decided to release their name and addresses on the internet. People c…

AFAICT it's impractical to keep residential addresses 100% private/secure - too many ways to get an address from any number of companies, organizations and governments that collect it for various reasons.

Plus numerous ways to infer your address from other data sources, including apps that grab GPS on friends' cellphones when they visit, etc.

Finally, shutting down paid data brokers seems virtually impossible in practice, which means anybody googling you can pay $20 and get everything.

Remember, the issue isn't lazy goodguys but even slightly motivated badguys, who then use third party scripts to do the data collection.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#65

Employees at Signal must be getting bribes as well, or even threats of violence since they can get nation state Secret communications these days. Got to make it so employees can’t do anything nefarious. This helps protect them.

How would employees of Signal access the encrypted messages?

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#66
It's really unfortunate that KYC regulations required Coinbase to have this information in the first place. We should be establishing strong social norms against sharing PII without a legitimate reason; this is not just an individual theft risk but a national security risk. Coinbase doesn't pay into your Social Security account, so they shouldn't have your Social Security number. They don't visit your house, so they shouldn't have your address. Etc.

Historically, although KYC regulations were widespread in Communist countries, they were unthinkable in most democratic countries until 9/11, which provided spy agencies with their golden chance to write their wishlist into law. But unfortunately that helps foreign spy agencies just as much as, maybe more than, it helps domestic ones.

In https://en.wikipedia.org/wiki/Know_your_customer#Laws_by_cou... you can see when they were introduced in different countries.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#67
post #19

Earlier quoted context omitted.

[flagged]

I thought hackers always had the hood covering thier head!

So obviously he's not the bad guy here, since his hood is down. :)

Yet he's a bit urban edgy here, and the staging is like it's an impromptu social media reaction to some online slight. (though reading a script)

You don't want to go full South Park "We're sorry", but I'd feel better about a response in a business dress shirt, out of respect for wronged customers.

With a bit more humbled posture.

IMHO, you're answering to customers you've wronged, and you don't wear a hoodie to church nor court (nor do you play video games during a live TV interview), nor do you assert superiority over the people you let down.

You can convey respect and humility, while also conveying being capable of responsibly resolving the problem.

(Just one person's reaction. I see some things the video did right, IMHO, but some other things jump out as wondering why they did that.)

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#68
post #47

Earlier quoted context omitted.

A shared or hashed secret would do it. Plenty of exchanges don't know their customers, and in fact that is how they get their customers.

No. Coinbase deals with fiat money, therefore subject to AML and KYC regulations.

That's not related to customer support, though. It's more like customer surveillance.

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#69
post #57
post #48

Earlier quoted context omitted.

Isn't the whole point of crypto to keep PII out of it completely? If not, what is all this non-sense for exactly, other than the typical goals of pyramid schemes?

The main point of crypto IMO is to have a large-denomination bearer asset. This is overlooked most places but if you examine around the time the FATF finally pretty much eliminated bearer bonds, bearer stocks, and large bank notes was exactly the time crypto really took off.

this? https://www.investopedia.com/terms/b/bearer-instrument.asp

Re: Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom

#70
post #47

Earlier quoted context omitted.

A shared or hashed secret would do it. Plenty of exchanges don't know their customers, and in fact that is how they get their customers.

No. Coinbase deals with fiat money, therefore subject to AML and KYC regulations.

The question was about customer support. AML and KYC regulations do not require that customer support persons know your PII. That can be kept firewalled from them.
Post reply on HN