Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

91–100 of 287 posts

Re: Coinbase Breach Notification

#92

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

How about allowing users to turn off sms.

Re: Coinbase Breach Notification

#93
post #78
post #33

I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

The FDIC is a government agency created after bank runs were common during the Depression. This is much different, nothing has been "reinvented".

After all, crypto is speedrunning 500 years of bad economics...

Re: Coinbase Breach Notification

#95
post #30

Earlier quoted context omitted.

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

There are hybrid systems which offer the best of both worlds. For example, the open source Muun wallet uses a 2-of-2 key system[0] in which Muun only has access to one of the two keys so, unlike a traditional bank or a custodial exchange like Coinbase, they can't spend any funds without your signature. Your Muun wallet app also only has one key, so authentication with the Muun service is necessary to complete transactions—this allows Muun to disable the wallet in the event the phone is lost or stolen, by refusing to countersign its payments. A recovery code kept offline, on paper, allows you to set up a new Muun wallet and recover your funds in the event that the phone holding the original wallet becomes unavailable for any reason. Finally, for complete self-custody you can export a PDF with encrypted versions of both keys plus some additional data ("output descriptors") which, together with the offline recovery code, can be used in an emergency to transfer your funds to a new wallet without any involvement from Muun.

This does involve using a centralized service to an extent, but the amount of trust you are asked to extend is limited. They can't unilaterally take your funds, and they can't stop you from moving them to another wallet which you fully control. At the same time, you can safely use the wallet online with the additional convenience and safeguards provided by Muun, and it would be difficult to lose your funds permanently from "one small mistake".

[0] https://blog.muun.com/muuns-multisig-model/

Re: Coinbase Breach Notification

#96

Earlier quoted context omitted.

I don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.

The important part is having physical access to the phone. A targeted attack against you now requires a physical element, rather than being entirely online.

Agree with everything you say, but add to that a lot of sms 2fa exploits are sim or redirection attacks. It’s possible to get access to a phone number without access to the phone.

Here’s an old story of a friend who had a weird talk with someone who had redirected their phone:

https://williame.github.io/post/24949768311.html

Re: Coinbase Breach Notification

#97
post #33

I like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.

Theoretically every bank was self-insured back in the pre FDIC era... the problem was that some banks didn't actually have the reserves (especially given fractional reserve banking)

Re: Coinbase Breach Notification

#98
post #71
post #61

I'm done with anything crypto. Daily. Bug after bug, breach after breach. I just don't see how, at any point in the future, crypto gets any more secure than, say, Microsoft Windows. There'll always be a bug, there'll always be a fix needed. And this isn't, "oh, my software crashed for an afternoon", it's potentially a good chunk of your life savings. I'll take my chances with the banks and Nigerian Princes.

checkout rekt.news to follow attacks in crypto world. It's wont stop, not just crypto but almost everything that involves software will have potential attacks. Crypto is just another area where attacks happen. IMO More the attacks, over the time crypto industry will become more robust.

I use to work with regulators on ACH and bank account fraud, in the legacy payment systems

It is so commonplace and high volume that it is not news

If incidents were listed alongside unexpected crypto seizures, crypto would look like the better option whether it was onchain, smart contracts or custodial institutions (like Coinbase) involved. And that has nothing to do with the size of the respective markets

Its not a contest, but anti-crypto people or skeptics are just falling for clickbait at this point and it’s pretty goofy to see.

Re: Coinbase Breach Notification

#99

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

for many users the alternative is no 2FA at all

I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.

Re: Coinbase Breach Notification

#100

Earlier quoted context omitted.

Agree. Although I would like coinbase to move away from SMS 2fa

They already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.

> which is much, much worse.

This attack wouldn't have been possible if they didn't allow SMS 2FA, so I don't think that's fair to say at all.

Post reply on HN