4 ms·
I've raised the issue with Coinbase support before, and I don't know if it's fixed (this was probably last year sometime), but when I used to use Coinbase heavi
by divbit 10y ago
I've raised the issue with Coinbase support before, and I don't know if it's fixed (this was probably last year sometime), but when I used to use Coinbase heavily, it was actually impossible to turn off sms 2fa. Even now, I have totp codes, but still get an sms with a code whenever I try to login to their service.
This was a real issue for me and an actual real reason that I stopped using their service for most of last year, as I use google voice / skype for my number, it's not really two factor.
I mentioned this issue in an e-mail chain with their support ( and their response was basically that I should use authy instead of totp (Google-authenticator), or some weird workaround involving installing authy / uninstalling authy in a certain sequence which didn't work for me. However- we see here in this post, that all the attacker had to do to compromise the Authy was to compromise the phone number! (I also raised this issue with their support.)
Their response to the Authy question was that since Authy / e-mail are running on two different servers, it's considered 2-factor by them... hrm..