(OP, you are calculating your losses, but didn't specify what those losses were. Did the theif get your crypto?)
(OP, you are calculating your losses, but didn't specify what those losses were. Did the theif get your crypto?)
My account is locked, and I am pretty sure my funds are still there. It will be a significant loss, but not devastating as this was my non-primary investment account.
I still don’t know the full extent of my losses.
So far, my losses are primarily loss of billable time. I am not a litigious person, but I am also going to educate myself as to what ‘pain-and-suffering’ means. Both my personal and business bank accounts are ok. I now understand why banks do not use email addresses as the login id. The thief would not (easily) be able to align my email address with my bank login id.
Once through this, I plan disassociate any portion of my login id with my name.
You haven't even tried to regain access to it? Instead of spending time on HN you might want to reach out to Coinbase.
This is an important point and one I've been thinking about for years. There's so much discussion about using password managers and good password practices and 2fA but almost no discussion on how using a single identifier to log into all these various services is in itself a huge security vulnerability. If we had different login usernames for each service, gaining access to people's accounts would be that much more difficult.
Email should be reserved for communications and not double as a means for authentication.
What happens if a legitimate customer's phone gets lost and they quickly transfer the number and reset their accounts?
I think they should do a video call verification.
Video verification sounds reasonable, as would some wait time. What's not reasonable in that situation is a self-service fully automated account recovery via SMS and e-mail verification followed by allowing withdrawals.