23 ms·
Coinbase Breach Notification
- vngzs 5y agoCoinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.
- 8BPATUNNTBU 5y ago>> Coinbase made everyone whole No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than $2,000, but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service.
- toomuchtodo 5y ago> but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service. Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported. Eventually, the end state desired will be reached (regulation, customer service, insurance, pursuit of value theft, etc), it's just taking time for governments and Big Finance to catch up. EDIT: https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html https://www.cnbc.com/2021/10/01/defi-protocol-compound-mista... (DeFi bug accidentally gives $90 million to users, founder begs them to return it) https://en.wikipedia.org/wiki/Cryptocurrency_and_crime https://en.wikipedia.org/wiki/Cryptocurrency_and_crime
- rednerrus 5y agoWe already have all of those things.
- gregwebs 5y agoBitcoin is a self custody asset just like gold, and IMHO that and it's de-centralized exchange is actually where all the value comes from if it has any. People do own gold and store it on their own property as well. Gold owners also use responsible custodians when they don't store the gold themselves. I think bitcoin owners do not do the same because they want to have easy access to trading and there aren’t companies that both operate trading and are either responsible custodians or make it easy to use a different custodian for storage.
- wpietri 5y agoSo if its value is in it not being regulated and you think governments will catch up, you're saying that it will eventually become worthless. If so, I agree. I'm just surprised to see it stated so baldly.
- Seattle3503 5y agoSome exchanges have good customer service, but Coinbase isn't one of them. They went the route of minimizing customer support staff that many tech companies do.
- webinvest 5y agoBig difference! I have personal experience of Coinbase emailing me (in writing!) that I’d get a bank overdraft fee refunded from their system-wide mistake of double-charging cryptocurrency orders. This happened right before their IPO. Long story short, I was never refunded despite raising two support tickets. :(
- lambic 5y ago*Californian government.
- deleted 5y ago[deleted]
- detaro 5y ago> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?
- vngzs 5y agoIn the linked PDF, Coinbase does not claim to have knowledge of a vulnerability in their system (edit: though it does note "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process," I interpreted that as "we supported SMS account recovery at all" which is inherently broken [0]). The requisite two-factor bypass is detailed in the linked pdf: > Even with the information described above, additional authentication is required in order to access your Coinbase account. However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account. My guess is, because funds were stolen from users' accounts, the CA breach notification laws apply and this needed to be disclosed as such. However, that doesn't necessarily mean that Coinbase was technically "breached," only that customer accounts were compromised. If the attacker controls your personal email associated with Coinbase, accompanying passwords, and phone number, and you use SMS 2FA, then your funds were stolen. Otherwise, they were safe. That's my reading of the article. [0]: https://krebsonsecurity.com/2019/08/who-owns-your-wireless-service-crooks-do/ https://krebsonsecurity.com/2019/08/who-owns-your-wireless-s...
- deleted 5y ago[deleted]
- detaro 5y agoThey also say "we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process". What did they update if it wasn't due to a weakness on their side? EDIT: on reading some of their docs, recovery is supposed to be followed by the user submitting ID documents etc before they get full access back - maybe that's the part they didn't do before or that could somehow be circumvented? (which is a flaw, but still requires intercepting the SMS to use?)
- space_rock 5y agoAgree. Although I would like coinbase to move away from SMS 2fa
- agumonkey 5y agoI don't know about you, but in the days of smartphones, login + mail + sms seems pointless. The only lock is the pin code / fingerprint on your phone, since when that is unlocked, the attacker gets to trigger all validation steps.
- opheliate 5y agoThe important part is having physical access to the phone. A targeted attack against you now requires a physical element, rather than being entirely online.
- danuker 5y agoAssuming the phone is not remotely exploited.
- willvarfar 5y agoAgree with everything you say, but add to that a lot of sms 2fa exploits are sim or redirection attacks. It’s possible to get access to a phone number without access to the phone. Here’s an old story of a friend who had a weird talk with someone who had redirected their phone: https://williame.github.io/post/24949768311.html https://williame.github.io/post/24949768311.html
- mdavis6890 5y agoThey already support other forms of 2FA, so I guess you mean they should turn off support for SMS. Keep in mind that for many users the alternative is no 2FA at all (they don't browse HN and Krebs), which is much, much worse. Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.
- syshum 5y agoThey would not be required to have all that info for an attacker to steal if it was not for the ridiculous reporting and KYC laws of the US
- sangnoir 5y ago> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false identity" - however, that framing is necessary to make consumers accept, by default, the burden of clearing debts they were never party to simply because the defrauded party did not have adequately verify perpetrators identity.
- heleninboodler 5y agoA point very well made by Mitchell and Webb: https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- tompazourek 5y agoThis is brilliant.
- vngzs 5y agoI agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly. From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain. I would add that the users have some responsibility for losing their emails/passwords, but my initial framing insufficiently demands responsibility for the service providers in this instance. The service providers should be expected to take all reasonable steps to prevent fraud on their platforms, and that should include extra scrutiny of SMS-based authentication mechanisms (e.g., identity verification). This is why Coinbase paid them back, accepting some responsibility for the fraud.
- sangnoir 5y agoI fully agree that users are not absolved of all responsibilities or vigilance (e.g. over passwords/devices). I think the legal framework has to be overhauled to clarify the culpability of all parties involved, rather than the current "Sucks to be you" attitude towards consumers, who are the least powerful, and have the least agency in these issues.
- nickthemagicman 5y agoif they did a SIM swap that means that they compromised the user's phone, if I'm not mistaken.
- sneak 5y agoYou are mistaken. A SIM swap is a compromise at the carrier, not the handset.
- nickthemagicman 5y agoAh so how is this Coinbases fault I also dont understand? Seems like a carrier issue.
- sneak 5y agoCoinbase shouldn't have been using SMS as 2FA to begin with. They also had a security bug in their SMS-based recovery system, according to other commenters in the thread.
- RangerScience 5y agoHuh. 3 or so years ago, I got SIM-swapped and they ran away with my Coinbase crypto, and CB definitely never made me whole.
- tgtweak 5y agoIt was not a simswap/simjack attack, they exploited an oversight in coinbase's password-reset 2fa to send the challenge code for one user to another user's phone number.
- vngzs 5y agoI haven't been able to verify these sort of claims any more than I've been able to speculate it was blanket telco Letters-of-Authorization (LoAs) [0][1] or classic SIM swaps that resulted in the account takeovers. I'm not claiming you're wrong, but given the timing of the LoA fraud and the attacks, it seemed likely to me that this was not an actual web vulnerability. What makes you believe a specific exploit like that existed against Coinbase's 2FA? And if it existed, then why wasn't that caught in a routine pentest? [0]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/ https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s... [1]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-anything-203c41361c80 https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
- tyingq 5y agoCoinbase themselves called it "a flaw in Coinbase’s SMS Account Recovery process".[1] I don't think they would have used that phrasing if it were individually simjacked phones. [1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Notification.pdf https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...
- vngzs 5y agoWith only the pdf to go on, I address the "flaw" in more detail in these comment threads [0] [1]. In short, I believe the "flaw" is likely to be "we used SMS for identity verification, without additional necessary scrutiny." The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special technical abilities, and therefore they are likely. Since the onus is on Coinbase to do identity verification in account recovery, a large number of successful takeovers would be a "flaw" in their process, even if it's not a technical flaw (which I would expect to be expressed in language like "vulnerability"). Accepting untrusted, unauthenticated user input as a SMS verification number would be a serious login-related flaw, and certainly Coinbase pentests their login pages. Any competent pentester would discover such a flaw. So between "Coinbase shipped a critical and obvious login flaw to prod" and "a routine and common criminal tactic was employed successfully against them," I find the latter more likely. [0]: https://news.ycombinator.com/item?id=28720101 https://news.ycombinator.com/item?id=28720101 [1]: https://news.ycombinator.com/item?id=28720520 https://news.ycombinator.com/item?id=28720520 [2]: https://xkcd.com/2176/ https://xkcd.com/2176/
- tobstarrr 5y agoQuestion as they did not mention Sim Swap in the email. Was this confirmed somewhere? "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account". I'm personally more familiar with incidents using SMS stealers (mobile malware) or use of SS7 vulnerabilites due to my job. Telcos in our country (europe) run tight security on SIM swaps. I was surprised about their recommendation to use time-based OTPs. They basically have the same attack vectors as SMS minus independent channel sign-what-you-see capabilites. Edit: Answer was in other comments
- hourislate 5y ago>(not because of Coinbase's fault) From the Coinbase statement >the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process Your speculation and conjecture dismisses you from any and all future discussions on this matter. You have demonstrated that your are unfit to comment.
- 5faulker 5y agoFunny that Canada is the other way around (gov.ca)
- amznthrwaway 5y agoAttackers did not have to perform a sim-swap attack. Coinbase provided a refund of the dollar value of the assets when they were taken, _not_ a return of the same assets. I’d appreciate if you update your comment to be accurate; though I fully understand that you are being intentionally dishonest out of disrespect to HN users. And I fully understand that dishonest comments like yours are considered to be absolutely acceptable by Dan Gackle.
- mmaunder 5y ago> "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach 6000 customers affected. If it wasn't a YC company you'd never say that.
- hartator 5y ago> i.e., compromise of Coinbase's infrastructure How is this not? 2FA is not to 2FA is you can recover your account with just a text. It does seem a bad engineering decision on their side.
- biushdfjsdf 5y agoEven though I stopped using coinbase, I appreciate the company compared to others because: 1) They had a reasonable account recovery process after I lost my phone and therefore google authenticator. Binance's process was needlessly annoying and pointless, kucoin straight up decided this was a good opportunity to just block my account completely and steal my money, even after email verification, as well as me supplying all emails they sent me about account activity. 2) They were the most transparent about new requirements about identity verification than others, and still allow withdrawals without verification. 3) Best UI in the game.
- danuker 5y agohttps://web.archive.org/web/20211001153920/https://oag.ca.gov/ecrime/databreach/reports/sb24-545815 https://web.archive.org/web/20211001153920/https://oag.ca.go...
- newfonewhodis 5y ago> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > access to this information "these" being username, pw, phone number etc. And then: > We have not found any evidence that these third parties obtained this information from Coinbase itself. You're technically correct but the first claim undermines the second one to me.
- andiliu 5y agoNot necessarily. You can collect information such as username, passwords, phone numbers from leaked databases and then attempt to login via Coinbase. Some might have 2FA, so they might even go as far as to sim swap them given that they know their phone number. So it doesn’t necessarily mean they got it from Coinbase.
- devrand 5y agoI don't see the conflict with those statement. They're saying "we don't know where the information came from and we haven't found any evidence that it came from Coinbase itself". It's difficult to prove a negative here until you find where the stolen credentials originated from. They're just saying that they have no evidence that it came from themselves thus far.
- mdavis6890 5y agoHow? Those statements seem entirely consistent and reasonable to me. They have no evidence or reason to believe that the information was stolen from Coinbase, but beyond that they don't know how attackers got it. Your car was stolen. I haven't been able to determine conclusively who did steal it or how, but I know it wasn't me.
- addingnumbers 5y ago"I know it wasn't us" is exactly the non-sequitur conclusion they were trying to walk you toward by wording their statements as they did.
- lbriner 5y agoWhat can be said that has not already? It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork" Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police. Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your millions of dollars of virtual currency?
- deleted 5y ago[deleted]
- bdcravens 5y agoCoinbase is not an unregulated free-for-all. They are licensed in all 50 states, and is registered as an MSB with FinCEN. https://www.coinbase.com/legal/licenses https://www.coinbase.com/legal/licenses
- arcticbull 5y agoMSB licenses mean basically nothing. Money transmitters are borderline unregulated, certainly depending on which state they obtained their licensing. They were actually created as a much lighter weight framework to avoid the onerous regulation of an actual depository institution.
- codingdave 5y agoThat page does not list all 50 states, just FYI.
- alphabet9000 5y agostates not listed: California, Hawaii, Indiana, Massachusetts, Missouri, Montana, Utah, Wisconsin, and Wyoming
- jefftk 5y agoIn order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the information described above, additional authentication is required in order to access your Coinbase account. However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account. We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost
- Fiahil 5y agoWell, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.
- vngzs 5y agoAnyone care to speculate what the flaw in their SMS recovery flow actually was? It's hard for me to think there's even a safe way to implement SMS based account recovery. They would be smarter to just turn it off.
- floatingatoll 5y agoI do not have specific answer for Coinbase. Typically, the flaw would be in modifying one of the form inputs to get the code delivered to a different phone number. That usually works out to either modifying the "destination number" client-side form value, or swapping in an edited/reused session token from a different login session's MFA challenge, to exploit missing ownership checks on the various underlying pkey object IDs.
- laulis 5y agoCould be SIM swapping? https://therecord.media/hackers-bypass-coinbase-2fa-to-steal-customer-funds/ https://therecord.media/hackers-bypass-coinbase-2fa-to-steal...
- IceWreck 5y agoFrom what I understand, the SMS verification was bypassed but not the password validation. I am probably not understanding this correctly, but if the attacker had to have knowledge of your password then why did they reimburse affected users. They could've called it a day and claimed it was the user's fault.
- matchagaucho 5y ago"Between March and May 20, 2021, you were a victim of a third-party campaign..." There were a spat of Coinbase SMS phishing texts in July 2021. So the window could be much longer, and the campaign ongoing.
- q1w2 5y agoYes, I also received several obviously fake SMSs in June 2021, so the window is clearly longer than what they are saying.
- thinkharderdev 5y agoYeah, I was getting the same phishing SMS weekly related to my Coinbase account.
- BitwiseFool 5y ago>"We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to admit that you are far more likely to be compensated in the event of an attack if you are using a large exchange. Not guaranteed, of course, but Coinbase has an image to maintain. I also believe, personally, that a large exchange has much better security than anything I could muster with a hot wallet. Yes, I know I can airgap a cold wallet but I like the ability to quickly sell some amount of crypto at market rates without having to transfer from a paper wallet. I also worry about physical security since my home has been burglarized before. Therefore, I keep my coins on exchanges and follow good practices with 2FA across my accounts (no SMS for any) and have withdrawal delays / whitelisting active.
- CPLX 5y agoWonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.
- ekianjo 5y ago> differentiate the coins at all from regular banking Apart from the fact that you can save value over time? Because the dollar is only going down.
- NineStarPoint 5y agoYou can verify that one bitcoin you have today will not be diluted by more than a certain amount tomorrow. Value is based on people’s value of the object though, and I wouldn’t necessarily bet on Bitcoin keeping that over the long term.
- 5y ago
- mdavis6890 5y agoI think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll guess the users had the same usernames and passwords that they've used for a hundred other sites, and one of those got breached at some point. Don't do that!
- deleted 5y ago[deleted]
- gowld 5y agousername and phone is not security factor. password is 1FA. SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
- mdavis6890 5y agoThe attackers also needed to know the user's phone number and have access to their email account. That is a sufficiently high bar that I can still be sympathetic to Coinbase here. Not sure why you discount username and phone either. Each of these is an additional layer of security simply by being more information an attacker needs to collect and associate. Coinbase doesn't publish a list of usernames. And how would someone associate phone numbers back to them?
- draygonia 5y agoYou can easily check databases on and off the darknet to find people's phone numbers and most people don't have multiple phone numbers and rarely change their number because of the associated hassle with moving accounts. The same goes for their email and even passwords if they reused them.
- 5y ago
- jtchang 5y agoI like this. They are basically making a call to self insure against these types of incidents and paying out of their own coffers. It makes sense since recovering the stolen crypto is near impossible (as designed). It's funny how everything old is new again. We are just reinventing FDIC insurance for crypto.
- gowld 5y agoFDIC insures your account against bank's overall business collapse. It doesn't insure your personal account against bank robbery of your sepcific account (deceptively named "identity theft"). I don't think you'd get FDIC money back if an attacker got into your account. The bank might cover you if they agree it was their fault, similar to Coinbase.
- tastyfreeze 5y agoThere is a difference between self insured and government insured. At the end of the day I prefer self or market insured so the business itself is on the hook for a breach.
- z3c0 5y agoNot a bad thing, really. It'll be what's needed to win over skeptics. I mean, they'll more likely just move the goalposts than be won over, but at least they're running out of things to complain about. Between this and the Coinbase card, Coinbase has already tackled the two biggest (valid) critiques of crypto that I hear.
- xqyf 5y agoThe FDIC is a government agency created after bank runs were common during the Depression. This is much different, nothing has been "reinvented".
- rhinoceraptor 5y agoAfter all, crypto is speedrunning 500 years of bad economics...
- htrp 5y ago
- skybrian 5y agoWhy does this say “Submitted Breach Notification Sample” and “Sample of Notice?” How do we know the sample is real?
- detaro 5y agoBecause it's a sample of what the communication each customer got looks like (with e.g. a placeholder for the customer name)
- rednerrus 5y agoSMS 2FA is not a good idea.
- paxys 5y agoSMS-based 2FA needs to die.
- flarex 5y agoIt's the easiest to use because of the prevalence of phone numbers and transferability between phones. These properties that give it the best user experience also make it the worst form of 2FA. TOTP and hardware keys are more secure but they are easier to lock yourself out of the account.
- LightG 5y agoI'm done with anything crypto. Daily. Bug after bug, breach after breach. I just don't see how, at any point in the future, crypto gets any more secure than, say, Microsoft Windows. There'll always be a bug, there'll always be a fix needed. And this isn't, "oh, my software crashed for an afternoon", it's potentially a good chunk of your life savings. I'll take my chances with the banks and Nigerian Princes.
- cableshaft 5y agoBanks are basically all software too now. They can have the exact same issues. They're not just taking your bills and storing them in a physical vault for you to take out later.
- pgwhalen 5y ago> They can have the exact same issues. I don't know if this is right. Traditional money transfer is not some absolute, irreversible thing. It is the product of software yes; but more importantly, it is the product of trust between institutions and individuals, backed by government and the legal system. In traditional finance, there is _far more_ than just the correctness software ensuring the safekeeping and transfer of your assets.
- jp42 5y agocheckout rekt.news to follow attacks in crypto world. It's wont stop, not just crypto but almost everything that involves software will have potential attacks. Crypto is just another area where attacks happen. IMO More the attacks, over the time crypto industry will become more robust.
- vmception 5y agoI use to work with regulators on ACH and bank account fraud, in the legacy payment systems It is so commonplace and high volume that it is not news If incidents were listed alongside unexpected crypto seizures, crypto would look like the better option whether it was onchain, smart contracts or custodial institutions (like Coinbase) involved. And that has nothing to do with the size of the respective markets Its not a contest, but anti-crypto people or skeptics are just falling for clickbait at this point and it’s pretty goofy to see.
- tolulade_ato 5y agoData security is a serious matter, one of the reasons we are building a product for this for businesses.
- rohitpaulk 5y agoCurious what the total dollar amount involved was.
- LightG 5y agoMe too. Everyone is cooing that they "made everyone whole". What if they weren't able to.
- rglover 5y agoReminder: if you don't own your keys, you don't own your cheese. Hardware: https://trezor.io/ https://trezor.io/ https://www.ledger.com/ https://www.ledger.com/
- therein 5y agoAlso https://coldcardwallet.com/ https://coldcardwallet.com/
- q1w2 5y agoKeeping your life savings in cash under your mattress is more stressful than relying on a bank.
- rglover 5y agoDo you need me to hold your hand when we cross the street?
- q1w2 5y agoI'm not crossing a street with you if you're carrying $500K in your backpack everywhere you go. Physical possession of wealth is a bad long term strategy. Eventually people WILL find out, and you WILL become a target. One of the main functions of government is private wealth protection. Banks are a feature, not a bug.
- rglover 5y agoAnd when they do and I do, I have a large cache of weapons and ammunition to wave at them with. If you think the government is protecting your wealth, you're incredibly naive.
- vladTheInhaler 5y agoSo you have to be strapped whenever you want to visit Starbucks? No thanks.
- joelbondurant 5y agoDelete Coinbase.
- rhacker 5y agoAlmost every exchange supports TOTP, as well as Coinbase, shouldn't they just disable SMS? Although it sounds like these are email accounts that have been hacked in other ways too.
- tibiahurried 5y agoThese platforms should not offer 2fa with SMS. And force their customers to use 2FA via MFA instead.
- wyck 5y agoDon't assume they don't. Most platforms not only enable multiple forms of security, you even get rewards if you choose better security. I use an exchange the uses double security, meaning you have 20 seconds to verify via email and 2FA, and on top of that the logins, withdrawals and transfers all have sperate passwords..and your able to rate limit them based on time periods. Most of the knew jerk reactions in here really don't see to know very much about how this actually works and how it's actually the users responsibility at the end of the day.
- tibiahurried 5y ago> you even get rewards if you choose better security Service providers should know better than their users and make the best choices for them. It is not like when you buy a car you get to choose whether you want airbags or not. They decided for you, and you must have airbags, period. Users, on overage, do not posses the knowledge to make the best decision when it comes to security. They go with the least friction solution. SMS works great everybody know how they work. So, yeah, the burden and responsibility should not be on the end user. This is clearly companies' fault.
- tfang17 5y agoAnother reminder that text-based 2FA is not secure.
- thinkharderdev 5y agoSecure/not-secure is not a binary distinction. And SMS-based 2fa is still more secure than password alone. One thing I've become painfully aware of recently is how all MFA is rendered pretty insecure by various "fallback" processes. I recently switch jobs and realized I had a few accounts using my old work phone as SMS 2fa number. In every case it was ridiculously easy to call a CSR and get 2fa disabled from their end.
- DennisP 5y agoFallback processes are the way SMS can make things worse. Report a lost password, verify yourself with your SIM-swapped SMS, maybe apply a little social engineering. I'd rather have just a strong unique password than use SMS. (And of course I'd much rather have good 2FA.)
- deleted 5y ago[deleted]
- get52 5y agoOnce again the crypto guys are getting horsefucked, why do people keep falling for the crypto scam
- babyshake 5y agoCoinbase has already contacted all affected users?
- YeBanKo 5y agoOne thing that cryptocurrencies achieved is they introduced a private key authentication at scale. For a moment, there was a hope that we can move to private key authentication mechanism. But, unfortunately, it was quickly rolled back by introduction of custodial wallets and we got pulled back into world of passwords.
- sneak 5y agosneak’s law: users can not (and a tiny subset of users that actually know how to, will not) securely manage* key material. *manage: generate, transmit/sync, authenticate, back up Discussion: https://youtu.be/9k4GP3Evh9c https://youtu.be/9k4GP3Evh9c I actually operate a business that exists solely as a result of this fact. If you give a user a key, they will lose it. If they’re a customer, you need to have a back up plan for what happens when they lose their keys.
- YeBanKo 5y ago> users can not (and a tiny subset of users that actually know how to, will not) securely manage* key material. True. And the is also true for password. Sure, generation is different and a way to authorizing a transaction is different, but otherwise form usage perspective password can be viewed as a primitive case of a private key. And industry made a huge progress in password authentications: password managers, OTP, biometric authentications, WebAuthn, etc. Specifically password managers and biometric authentication mechanisms can be re-used for private keys as well. Having multiple wallets, multisig authentication and smart contracts allows to have recovery paths, while making sure that varios custodians can only perform certain transactions and in a transparent way.
- encryptluks2 5y agoIf you got hacked and don't get your funds deposited. Good luck getting in touch with anyone. I have sent multiple requests to another issue, was told I should expect a response shortly and that was months ago.
- sneak 5y agoHigh security services should send a pair of U2F keys to each and every customer when they sign up (or hit a retention/value threshold), with instructions on how to store them (that is, different buildings). Then they can use normal app-based 2FA day to day (NOT TOTP as that is phishable), and use the preenrolled U2F hardware tokens as recovery methods when the user inevitably loses their phone and needs to re-enroll their primary 2FA device (the service app on their new phone). Falling back to SMS to reset 2FA, or Skype calls where you hold up your ID with a CSR or whatever is just asking for shit like this. In bulk the hardware is probably <$5/token, so well under $10/user (probably closer to $5/user even for a pair of tokens). If your CLTV for your high security financial service can’t afford that, go do something else. This is a solved problem; the fact that financial institutions have not got on board with 10+ year old stable, cheap, widely available technology is a market failure caused by massive overregulation. Nothing about this is hard, nothing about this is expensive, there’s just a pervasive attitude in financial technology circles of “this is the way we’ve always done it” or “this is the way everyone else does it”, even if those ways encapsulate a ton of waste and risk. Even without the whole “n+1 tokens, used only as primary 2fa recovery” scheme, I don’t think there’s a single US retail bank that supports U2F even for normal 2FA login. It’s shameful. This industry is so ridiculously ripe for disruption but it’s so heavily overregulated that nobody that doesn’t suck is allowed to enter the market. Simple was the first to try (and even they had to use a partner bank) and they got erased via acquisition (and I think subsequently shut down).
- thinkharderdev 5y agoAt this point I think the thing holding back U2F is just user experience. It is not "hard" but it is a pain in the ass and most people just find it annoying. The other issue is that you ultimately need some sort of fallback mechanism if someone loses their keys. And it will happen. So you still end up with a process that can be socially engineered, which is generally the weak link in any authentication system.
- sneak 5y agoThe pain in the ass is why it should be used as an primary app-based 2FA recovery mechanism. Doing 2FA via app is fine for most users. The failures happen when users lose their phone and need to reset 2FA. That's where the pain in the ass (but secure pain in the ass) of U2F would come in handy, to re-enroll primary 2FA. Nobody presently has good ways of doing 2FA resets. U2F hardware is a near-perfect solution.
- Ansil849 5y agoWhat I'm getting from this is that Coinbase was/is using SMS-based 2FA? Using anything short of mandatory U2F means the responsibility of this breach firmly falls on Coinbase's shoulders. It's like if you found out your bank uses single-bolt doors for its vault.
- thinkharderdev 5y agoIs there any d2c business anywhere in the world right now that requires U2F on all accounts? I think you underestimate how confusing all of this is to non-technical users.
- Ansil849 5y agoPlenty of banks require HOTP dongles. Those are, if not more confusing, than certainly on par with U2F dongles. Meaning if banks can do HOTP, they can do U2F, and using "confusing to consumers" is not an excuse.
- thinkharderdev 5y agoWhich banks require an HOTP dongle for customers. Maybe it is a non-US thing but I have never once seen that.
- ed25519FUUU 5y agoThe fact that there’s no OTP option even available is what bothers me. Let the power users use OTP if they want it. When OTP is available I always remove my phone and use that. Sim swap is such a common attack these days.
- DennisP 5y agoCoinbase supports Google Authenticator, and also hardware keys like Yubikey. https://help.coinbase.com/en/coinbase/getting-started/verify-my-account/how-do-i-set-up-2-factor-authentication https://help.coinbase.com/en/coinbase/getting-started/verify...
- Animats 5y agoThe attack still goes on. Email today: Coinbase Coinbase <https://verify-customers.elastic-galileo.185-150-117-78.plesk.page/> Verify your email address In order to continue using your Coinbase account, you need to reconfirm your email address. To avoid service interruptions verify your email. Verify Email Address <https://verify-customers.elastic-galileo.185-150-117-78.plesk.page/> If you did not sign up for this account you can ignore this email and the account will be deleted. Get the latest Coinbase App for your phone Coinbase iOS mobile bitcoin wallet <https://verify-customers.elastic-galileo.185-150-117-78.plesk.page/> Coinbase Android mobile bitcoin wallet <https://verify-customers.elastic-galileo.185-150-117-78.plesk.page/> Whois info: > whois plesk.page Domain Name: plesk.page Registry Domain ID: 41B85291E-PAGE Registrar WHOIS Server: whois.namecheap.com Registrar URL: https://www.namecheap.com/ Updated Date: 2021-07-10T14:00:29Z Creation Date: 2020-03-18T03:06:27Z Registry Expiry Date: 2022-03-18T03:06:27Z Registrar: Namecheap Inc. Registrar IANA ID: 1068 Registrar Abuse Contact Email: abuse@namecheap.com Registrar Abuse Contact Phone: +1.6613102107 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Registry Registrant ID: REDACTED FOR PRIVACY Registrant Name: REDACTED FOR PRIVACY Registrant Organization: Privacy service provided by Withheld for Privacy ehf Registrant Street: REDACTED FOR PRIVACY ... Traceroute shows that site hosted by Hurricane Electric. Anyone who lost money in this should sue Namecheap and Hurricane Electric. They will be stumbling all over themselves to tell your lawyers who their customer was, to avoid liability. I don't even have a Coinbase account.
- koheripbal 5y agoI've been targeted as well, and there is no way "social media" was a source for my coinbase account details, as the coinbase statement implies. I am 90% certain Coinbase has suffered a broad breach of customer data that they have not disclosed yet.
- Thorrez 5y agoAnimats doesn't have a Coinbase account. Clearly the phisher got Animats's email from some other source than Coinbase. https://haveibeenpwned.com/ https://haveibeenpwned.com/ says my data has been leaked ~25 times.
- rStar 5y agocouldn’t happen to nicer people
- thepasswordis 5y agoHere's the lesson: Use yubikeys. Use coinbase vaults.
- tgsovlerkhgsel 5y agoI wonder how "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident" is to be read. To me, that reads as "if you had 1 BTC stolen on May 20, we will deposit 40k USD into your account, because that was the value of 1 BTC as of May 20", not "if you had 1 BTC stolen, there is now 1 BTC back in your account". The timeframe listed in the letter covers exactly the time of a massive price spike, so a USD payout would put most people in a better situation than a BTC payout in this specific case, but I'm still curious how this is handled, and whether there is a universally agreed standard for it. Because next time "we'll reimburse you the USD value of your crypto as of the date of the attack 6 months ago" could mean that someone "made whole" like this has only 10% of what they would have if the attack didn't happen.
- freeAgent 5y agoI also find that to be a weird stance. People can hold USD or stablecoin a on their Coinbase account if they wish. For people who choose to hold assets other than USD, it seems more logical to replace those assets. Coinbase already trades all of them. Or, since this was a Coinbase flaw, allow the user to choose whether they want the original assets restored or the dollar value at the time of theft (since in theory they could have sold). This way Coinbase feels more pain, but customers should be happy because they come out no worse and possibly better off.
- tgsovlerkhgsel 5y agoThe PDF link (https://oag.ca.gov/system/files/09-24-2021%20Customer%20Notification.pdf https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...) was sometimes throwing a "file not found" error. Archived version: http://web.archive.org/web/20211001155216/https://oag.ca.gov/system/files/09-24-2021%20Customer%20Notification.pdf http://web.archive.org/web/20211001155216/https://oag.ca.gov... (consider https://archive.org/donate https://archive.org/donate to support the cost of operating the archive).
- rsimmons 5y agoThe irony in that breach document that the first credit monitoring agency mentioned at the bottom is Equifax, having the reputation for one of the worst data breaches in 2017 spanning nearly 150mil American citizens.
- deleted 5y ago[deleted]