Edit: California, not Canada. My bad.
Edit: California, not Canada. My bad.
Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure.
I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false identity" - however, that framing is necessary to make consumers accept, by default, the burden of clearing debts they were never party to simply because the defrauded party did not have adequately verify perpetrators identity.
From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain.
I would add that the users have some responsibility for losing their emails/passwords, but my initial framing insufficiently demands responsibility for the service providers in this instance. The service providers should be expected to take all reasonable steps to prevent fraud on their platforms, and that should include extra scrutiny of SMS-based authentication mechanisms (e.g., identity verification). This is why Coinbase paid them back, accepting some responsibility for the fraud.
And your mobile phone number is invaluable here.
why sms? because everyone has it. we're not in a otp/u2f only world yet. sms 2fa is better than no 2fa
https://www.theguardian.com/technology/2016/apr/19/ss7-hack-...
International tourists will also be less likely to get a local SIM card and then pay exorbitant roaming charges.
(Here in South Africa, clients must provide proof of their residential address. Some telcos even insist on verifying the thumbprints of their clients)
When I saw this happen, Google was not aware the number was gone, so calls and texts from other Google Voice users still worked.
https://arstechnica.com/information-technology/2021/03/16-at...
The cost benefit analysis probably does not make sense for a gazillion low balance users. It may make sense to enforce strong factors for high balance users. You have to balance that against them taking their business elsewhere.
SMS is handy but it should be a last resort rather than the main second factor.
SMS can be good enough to confirm a password reset link that was sent by email (so you will not really do anything without access to an account's linked email address), but not as the main second factor for login.
For traditional finance, it's pretty different. E.g., "If fraudulent electronic withdrawals are made from your bank or credit union account but your ATM or debit card is not lost or stolen, you are not liable if you write to let the bank or credit union know about the error within 60 days of when they send you the account statement showing the fraudulent withdrawals." https://ovc.ojp.gov/sites/g/files/xyckuh226/files/media/docu...
If you have a lot of money, most brokers will ship you a hardware token.
RSA enrollment is probably the single most challenging end user issue our IT folks deal with. After password reset it’s the #2 call, and lots of time, training and engineering effort has been expended to improve the experience. (And those efforts were very effective!)
... bank robbery by unknowing proxy. If we reframed the narrative, I bet banks and financial institutions would bust their asses to make things better.
What makes you believe a specific exploit like that existed against Coinbase's 2FA? And if it existed, then why wasn't that caught in a routine pentest?
[0]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...
[1]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
I don't think they would have used that phrasing if it were individually simjacked phones.
[1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...
The technical barrier to entry for accruing and using breach databases is near-zero [2], same with the barrier to SMS fraud. Both are routine and easy methods for criminal groups with no special technical abilities, and therefore they are likely. Since the onus is on Coinbase to do identity verification in account recovery, a large number of successful takeovers would be a "flaw" in their process, even if it's not a technical flaw (which I would expect to be expressed in language like "vulnerability").
Accepting untrusted, unauthenticated user input as a SMS verification number would be a serious login-related flaw, and certainly Coinbase pentests their login pages. Any competent pentester would discover such a flaw. So between "Coinbase shipped a critical and obvious login flaw to prod" and "a routine and common criminal tactic was employed successfully against them," I find the latter more likely.
[0]: https://news.ycombinator.com/item?id=28720101
Coinbase is very clear in the breach notification that attackers had already acquired users' (a) emails, (b) passwords, and importantly (c) already have access to the users' primary email accounts. At that point, the only thing left preventing account takeover would be the 2FA challenge, and since Coinbase said there was "a flaw in Coinbase’s SMS Account Recovery process" I find it a bizarre conclusion to think that flaw was just a standard SIM-swap.
Edit: Actually, pretty positive it was not just a standard SIM-swap given that, if it were, Coinbase would not have specifically called out "a flaw in Coinbase’s SMS Account Recovery process". If it were just normal SIM-swapping bad guys would have just used that to defeat 2FA during the login process - there would have been no need for them to mess with the account recovery process. That's actually not that uncommon a bug, where 2FA works great to protect login, but there is an oversight that makes it not required during the account recovery process (by definition you're letting people into an account during the recovery process even if they're missing one of their authentication methods) that makes the whole 2FA moot.
How is it possible to update the SMS recover protocol to prevent sim swapping?
[0]: https://help.coinbase.com/en/pro/managing-my-account/account...
"However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account"
The key part being: "a flaw in Coinbase’s SMS Account Recovery"
[1] https://oag.ca.gov/system/files/09-24-2021%20Customer%20Noti...
No, I don't think they have. The document says they will, not that they have. I personally know someone who was had 2FA and tends to be security knowledgeable and was struck by this on 6/7, which is well past their claimed date, so either they are lying or the hacking continues undetected. He has had no ability to get anyone on the phone who will help with the issue. He lost less than $2,000, but it is ridiculous how crypto currency combines the worst of the wild west with the worst of banking with the worst of crappy customer service.
Crypto's value is because it is the wild west. Otherwise, it'd be gold: custodians holding the commodity for owners, most of it locked in cold storage, fully regulated, and governments pursuing theft whenever reported.
Eventually, the end state desired will be reached (regulation, customer service, insurance, pursuit of value theft, etc), it's just taking time for governments and Big Finance to catch up.
EDIT: https://www.cnbc.com/2021/10/01/defi-protocol-compound-mista... (DeFi bug accidentally gives $90 million to users, founder begs them to return it)
Gold owners also use responsible custodians when they don't store the gold themselves. I think bitcoin owners do not do the same because they want to have easy access to trading and there aren’t companies that both operate trading and are either responsible custodians or make it easy to use a different custodian for storage.
If so, I agree. I'm just surprised to see it stated so baldly.
Long story short, I was never refunded despite raising two support tickets. :(
Here’s an old story of a friend who had a weird talk with someone who had redirected their phone:
Coinbase should continue doing what they are doing, which is to support SMS, and educate and encourage users where possible to use something else instead.
I'm pretty sure people have phones and Coinbase can force them to install a 2FA app.
If your cloud account is protected by 2FA that's also in the cloud... it's turtles all the way down.
To verify someone's identity ("Identity Proofing") using Stripe Identity [1] costs ~$2. They support IDs from 33 countries, and have implemented fraud detection in the flow. If you were so paranoid as to defend against someone stealing your government issued ID (used in the proofing process), you could paper mail a OTP to physical address on file.
Does it suck and its the cost of no digital ID infrastructure in the US? Yes. Is it insurmountable? Not at all. At the end of the day, people are the weakest link, and we must fallback to meatspace trust anchors (in this case, possession of government provided ID that can be provided on demand with robust fraud detection mechanisms). You are who you are, and own what you own, not because of key material but because of the law.
This attack wouldn't have been possible if they didn't allow SMS 2FA, so I don't think that's fair to say at all.
Not just to lock down the logins to Coinbase, but to also secure their customers' email, Twitter accounts, and as many other online systems as would support hardware backed WebAuthn. Hell, PokerStars did this with RSA tokens back in 2008 so it's not like it's a new idea.
Please tell me how to do that?
Two iPhones and every type of Titan key that is currently sold, still haven't been able to make NFC work, nor authentication over Bluetooth.
That also solves a major usability issue: instead of trying to juggle between a mobile application and a TOTP authenticator (on the same device!), or plugging in a USB adapter for authentication needs, you just quickly tap/wave your keyring next to the phone. Or take your phone quickly by your pocket when you need the second factor.
(It’s also the only option offered by many US banks, which is a sad commentary on the level of tech innovation in finance in the USA.)
source? I kind of doubt that's something coinbase would call a flaw in their system?
> Even with the information described above, additional authentication is required in order to access your Coinbase account. However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.
My guess is, because funds were stolen from users' accounts, the CA breach notification laws apply and this needed to be disclosed as such. However, that doesn't necessarily mean that Coinbase was technically "breached," only that customer accounts were compromised.
If the attacker controls your personal email associated with Coinbase, accompanying passwords, and phone number, and you use SMS 2FA, then your funds were stolen. Otherwise, they were safe. That's my reading of the article.
[0]: https://krebsonsecurity.com/2019/08/who-owns-your-wireless-s...
EDIT: on reading some of their docs, recovery is supposed to be followed by the user submitting ID documents etc before they get full access back - maybe that's the part they didn't do before or that could somehow be circumvented? (which is a flaw, but still requires intercepting the SMS to use?)
The "flaw," in my reading of it, was to support SMS-based account recovery at all. But I'm not necessarily right here, and open to alternatives.
However, around the time of the breach date (March - May 2021), there were a number of "B2B" services that offered a "type in any SMS number and you will get all text messages to that number," type feature intended for customer support teams to use for shared SMS access. Those systems often had privileged access to telcos and were regularly exploited by attackers to break 2FA without even a SIM swap [1]. With those tools, stealing all SMS to a number required only intent, not conversations with telco support personnel.
[0]: https://news.ycombinator.com/item?id=28720280
[1]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...
1) They had a reasonable account recovery process after I lost my phone and therefore google authenticator. Binance's process was needlessly annoying and pointless, kucoin straight up decided this was a good opportunity to just block my account completely and steal my money, even after email verification, as well as me supplying all emails they sent me about account activity.
2) They were the most transparent about new requirements about identity verification than others, and still allow withdrawals without verification.
3) Best UI in the game.
From the Coinbase statement
>the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process
Your speculation and conjecture dismisses you from any and all future discussions on this matter. You have demonstrated that your are unfit to comment.
How is this not? 2FA is not to 2FA is you can recover your account with just a text. It does seem a bad engineering decision on their side.
6000 customers affected. If it wasn't a YC company you'd never say that.
They also had a security bug in their SMS-based recovery system, according to other commenters in the thread.