Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

71–80 of 287 posts

Re: Coinbase Breach Notification

#71
post #61

I'm done with anything crypto. Daily. Bug after bug, breach after breach. I just don't see how, at any point in the future, crypto gets any more secure than, say, Microsoft Windows. There'll always be a bug, there'll always be a fix needed. And this isn't, "oh, my software crashed for an afternoon", it's potentially a good chunk of your life savings. I'll take my chances with the banks and Nigerian Princes.

checkout rekt.news to follow attacks in crypto world.

It's wont stop, not just crypto but almost everything that involves software will have potential attacks. Crypto is just another area where attacks happen. IMO More the attacks, over the time crypto industry will become more robust.

Re: Coinbase Breach Notification

#72
post #5

What can be said that has not already? It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork" Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police. Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your mil…

Coinbase is not an unregulated free-for-all. They are licensed in all 50 states, and is registered as an MSB with FinCEN. https://www.coinbase.com/legal/licenses

That page does not list all 50 states, just FYI.

Re: Coinbase Breach Notification

#74
post #54
post #49

Earlier quoted context omitted.

And they would have had to do ~6000 SIM swaps? that seems like too many for a short period of time. Maybe?

There is some speculation in another comment that their SMS verification server may have actually had a technical flaw, and the issue was not a lack of separate identity verification on SMS [0]. However, around the time of the breach date (March - May 2021), there were a number of "B2B" services that offered a "type in any SMS number and you will get all text messages to that number," type feature intended for custom…

Interesting. thank you for the links.

Re: Coinbase Breach Notification

#77
post #58

Earlier quoted context omitted.

"I know it wasn't us" is exactly the non-sequitur conclusion they were trying to walk you toward by wording their statements as they did.

How else would you even word it? They accurately described the situation. If people are leaping to "I know it wasn't us" then that's their own misinterpretation.

> If people are leaping to "I know it wasn't us" then that's their own misinterpretation.

Is that not what we just watched a HN reader do with that analogy?

It would be equally accurate to say "We have no evidence that it wasn't our fault," either statement is equally meaningless when they have no significant evidence.

They chose to phrase their ignorance the only way that it could be misinterpreted as mitigating their liability, and we just watched that misinterpretation play out here.

"We haven't found any evidence of who was at fault" would be more forthright than answering only the half of that question that sounds better for them.

Re: Coinbase Breach Notification

#78
post #33

I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

The FDIC is a government agency created after bank runs were common during the Depression. This is much different, nothing has been "reinvented".

Re: Coinbase Breach Notification

#79
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

This seems like an egregious use of the word "literally" I think you should look up the use cases for decentralized finance.

Re: Coinbase Breach Notification

#80

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

Ok before I was locked out of my account for changing phone numbers they only had SMS
Post reply on HN