news.volyx.in

Coinbase Breach Notification (oag.ca.gov)

511 points by sunils34 · 1817 days ago · 271 comments on HN

Article summary

Coinbase has notified the California Attorney General's office of a data security breach, which resulted in the theft of customer credentials. The breach occurred due to a flaw in Coinbase's SMS account recovery process, allowing attackers to bypass two-factor authentication. Coinbase has updated its protocols to prevent further bypassing of this authentication process and plans to reimburse affected customers. The exact nature of the breach is still being discussed, with some speculating that it may have involved SIM swapping or other forms of attack.

Main themes

  • Coinbase breach
  • SMS 2FA security
  • customer notification and reimbursement
  • authentication methods
  • digital ID infrastructure
  • user education and awareness

What commenters say

  • The breach may not have been a traditional compromise of Coinbase's infrastructure, but rather a result of attackers exploiting a flaw in the SMS account recovery process.
  • Coinbase's decision to notify customers and reimburse losses is a proactive step to maintain customer trust, despite the breach not being directly their fault.
  • The use of SMS-based 2FA is inherently insecure and should be discontinued in favor of more secure methods.
  • Some users may not have alternative 2FA options, and disabling SMS 2FA could lead to a lack of any 2FA for those users.
  • The breach highlights the importance of educating users about the risks of SMS 2FA and the need for more secure authentication methods.
  • The use of emergency single-use codes or other backup authentication methods could help mitigate the risks of 2FA loss or compromise.
  • The lack of digital ID infrastructure in the US makes it difficult to implement more secure authentication methods, but it is not an insurmountable problem.
  • Forcing users to install 2FA apps may not be a viable solution for all users, particularly those who may not have access to a compatible device or may not be tech-savvy.