3 ms·
Actually, they didn't tell me the IP address. That X was in the original email. Also, my phone has a password on it, and the coinbase app and my Authy app both
by Psyonic 13y ago
Actually, they didn't tell me the IP address. That X was in the original email.
Also, my phone has a password on it, and the coinbase app and my Authy app both had passwords on them.
So actually, your scenario isn't analagous at all. But thanks for automatically assuming I'm to blame!
You honestly think it's entirely reasonable that someone was able to get past 2FA, take all my coins (+ purchase more) with no security check, and then to have CB give me nothing but radio silence for 3 weeks? Literally not a single word? And then finally tell me "That sucks."?
- Nanzikambe 13y ago> Also, my phone has a password on it, and the coinbase app and my Authy app both had passwords on them. What difference does that make to malware/trojans? Presumably they already have those. To elaborate: Trojan on phone catches passwords, phones home & hands them over to the malicious user. Malicious user initiates BTC transfer, uses trojan's remote command and control to bypass 2FA. Job done. From that perspective, whilst CB could see that a person from a given IP accessed and transferred from your account, what do you expect them to do? Come round to your house and forensically dissect your phone and PC to see what went wrong? Even if they did, to what end? It's not their problem, it's yours. If you want reaction, go report the crime. If you think Coinbase should refund your BTC, take them to court. Heck, do both. The chances of getting your BTC back are slim to none in any case.
- Psyonic 13y agoDude, what are you talking about? This is an iPhone (non-jailbroken.) Are you saying the official CoinBase app had a trojan? Or Authy, the most widely used 2FA app? If you're actually curious what I think they should do, we could talk about it, but I don't think you care beyond blaming the victim. What I don't understand is why you assume I MUST have done something wrong. Do you really think it's impossible that this was a weakness on their end? If 110 million credit cards can be stolen from Target, maybe it's possible API keys can be stolen from CoinBase?