Crypto.com accounts had unauthorized withdrawals
crypto.com
crypto.com
How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open them up to credential stuffing attacks? This is a really, really odd response to me. I can understand migrating to a new 2FA system, but they'd have to re-establish the chain-of-trust somehow. Are they just hoping that users don't have compromised email/SMS accounts in order to enable the new 2FA system?
If they literally removed 2FA from everyone, that's insane.
EDIT: They're #3 (bigger than Coinbase). Only OKX and Binance are bigger[1].
Coinbase is a large exchange...
It's definitely more established than crypto.com though.
Do you think crypto.com is larger than Binance?
Crypto.com is the #3 exchange and bigger than Coinbase[1].
crypto.com is a two bit player in comparison.
Cryptocurrency was not even supposed to have these pseudobanks called exchanges leading this space. It wasn't even supposed to be an "industry".
People were supposed to mine cryptocurrency on their own commodity hardware and use that to transact amongst themselves.
"Insanity is doing the same thing over and over again and expecting different results."
For me there are really only two alternatives. Negative interest on cash or competition among currencies (free banking). All those people shouting that Bitcoin should become the global reserve currency don't actually understand that a global reserve currency is a terrible idea and are only in it for the money.
If you want to deliver security then MFA is an interesting strategy that needs careful consideration and planning, you might end up building things like Security Keys so as to solve real threats. You might fix real problems (Google eliminated phishing) at your organisation.
But if your goal is to bamboozle fools into giving you their real money in exchange for Itchy and Scratchy money that you may or may not then "lose" then you don't need all that hard work. Take whatever nonsense you cobbled together and say it's "Two factor" because that means "good" to people who don't know any better.
And you are not asked to do this while logging in again. It is assumed you know why you have to reauthenticate and that you have to re-add 2FA in your app settings…
But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it.
Anyone know how the do auth on the app?
For users in the US there is no way to change the password, because the webapp (which might have that feature) is not allowed to be used from US.
Once I asked how to change password and support said I can change the PIN on phone and dont worry your funds are safe.
If you're speaking from experience as a user of their service, I strongly suggest that you use a different exchange. Gemini + Coinbase both have very easy-to-understand authentication systems. If you don't understand the authentication system, that's a good red-flag that you should take as a reason to move to a more trustable platform.
(Just my two cents, as someone who works on authentication system architecture design.)
I mean the app is tons better then Coinbase and I think a big reason that crypto.com is growing tremendously. Users like it.
An e-mail with a link to actually click? Does anyone else see those flashing red lights and hear that alarm klaxon? Please do me a favor and drop those assholes like a bad habit. They are going to cost you whatever assets of yours they have in their control.
> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure.
May the god guy didn't get the message that Crypto.com had an issue, because s/he is unavailable.
IE: single factor resets, so a compromised “2FA” was actually keys to the kingdom?
But you’d think the attacker would need access to a user’s email or some such then.
As a communications person, reading between the lines tell me they've got no idea what happened. Comforting!
https://www.latimes.com/business/story/2021-11-16/crypto-sta...
My understanding is that Enron's leaders were caught in fraud and that led to the collapse of the company—they weren't planning on it collapsing, so the investment actually made sense in that case.
I'm imagining it as '$700 million IN CRYPTO, which is of course better than money'. For a name: which could easily be restored if it turns out the payment is worthless. But that's just my fantasy of how this might have gone on.
If it's $700 million in real money that only underscores how desperate they are to make some colorful gesture.
When it's designed from the start to be an expanding shell powered by new belief coming in, the philanthropy and big gestures are core to the nature of what it is.
Back in the day I read an old book by Harvey Mackay (iirc), one of those business-guy self-help books, and he had a chapter called never buy anything big in a room where there is a chandelier. :D The point being, it's normal for scamsters to influence people by making their pitch in a place all decked out to look like the most wealthy, influential place you could imagine, and there'd be a chandelier because it would look like everybody was rich. And so, never buy anything big in a room with a chandelier, because it probably meant you were being ripped off.
All this predates crypto by a loooooong way. There's nothing really new. Maybe back in the days of travelling traders on camels it was, never buy a camel in a room with a carpet that's bigger than the camel is :)
> No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed.
> No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed.
so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from?
> transactions were being approved without the 2FA authentication control being inputted by the user.
the withdrawal system allows for non-2fa when its enabled, but informs the risk system when it happens? what kind of feature is that?
> While Crypto.com already performs internal and external penetration tests, Crypto.com has immediately engaged with third-party security firms to perform additional security checks
ah yes. the "we already had 7 double checkers, better add an 8th" solution. sounds like maybe the problem is not with the testing and auditing suite.
> releasing additional end-user security features as we move away from 2-Factor Authentication and to true Multi-Factor Authentication (MFA)
2fa isnt true MFA? did we evolve some new jargon im not aware of?
> WAPP is designed to protect user funds in cases where a third party gains unauthorized access to their account and withdraws funds without the user’s permission. WAPP restores funds
wait i thought they said they already did this? are they gonna start charging for it now because they lost money?
> To qualify for the WAPP program, users must: Set up an anti-phishing code at least 21 days prior to the reported unauthorized transaction
wtf is that? a PSK? a TOTP?
> File a police report and provide a copy of it to Crypto.com; and
hello, local police department? i need to file a report - my cryptocurrency wallet just had an unauthorized funds withdrawal. no, i dont have a suspect, or evidence, or any action for you to take. just come down here and write down that i said this happened please.
Crypto.com is on par with FTX, Binance, Celsius, Coinbase and we have many varying examples of their valuations and supporting revenues and balance sheets.
$30mm irrecoverably stolen with zero liability for the hacker? No problem for the user experience or health of the company these days.
I wouldn't touch crypto.com with a very long barge pole...
I don't know about crypto.com but this is how binance does it. You can enable 2FA for everything or individually for specific actions such as logging in, withdrawals, etc. Lets everyone choose their security/inconvenience trade-off which I find reasonable.
> wtf is that? a PSK? a TOTP?
There is something similar on binance too. You set up some unique code on their website, every official email they send you will include that code as proof of authenticity. A weak form of signature I guess.
I believe this is a system where you give a website something that you will recognize (I've seen small images used as well as text) that they agree to display to you in their layout. It is supposed to make building convincing phishing websites harder, as the attackers cannot know what content a given user has sent to the service.
Cryptocurrencies traded on exchanges are basically paper gold at this point.
Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less.
From the announcement, it looks like Crypto.com is making the users whole again;
> No customers experienced a loss of funds.
This means that (in some cases) Crypto.com was on the hook for much more than $71k / user. The WAPP appears to put a series of conditions on the user, and introduce an upper limit to the amount that Crypto.com will return in the future.
> WAPP restores funds up to USD$250,000 for qualified users; terms & conditions apply.
> Enable Multi-Factor Authentication (MFA) on all transaction types where MFA is currently available,
> Set up an anti-phishing code at least 21 days prior to the reported unauthorized transaction,
> Not be using jailbroken devices,
> File a police report and provide a copy of it to Crypto.com; and
> Complete a questionnaire to support a forensic investigation.
This looks more like a mechanism to limit Crypto.com's exposure to future events than it does a policy to protect users.
If not a centralized solution like above then what? We just allow stolen funds to be used now or any point in the future, rewarding criminal behaviour?
Any exchange or custodian has a non zero chance of getting hacked or inside-jobbed; unlike fiat currencies there is no judicial process that is going to maybe let me claw my stuff back.
A sort of fdic insurance for custodian crypto accounts, is an inevitable market solution.
>> No customers experienced a loss of funds.
Let's believe that when we hear someone other than the company saying it.
> File a police report and provide a copy of it to Crypto.com
Yeah, I'm sure tons of crypto holders will get right on that.
That's fine. It lays out the risk exposure in concrete terms and defining their market offering. If you use a jailbroken device, or have more than $250K in funds, or are holding crypto for illegal purposes, don't put it in Crypto.com. Same as FDIC insured savings accounts that are limited to $250K.
I mean, there's still plenty of money in other people's accounts they can use to cover the losses.
Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had. But personally I'd hate to bank purely on the internal controls of a Singaporean subsidiary of a Maltese company.
It s not each of the user individually seeing their balance go down, it s the company lying even more about its ability to liquidate all accounts.
Your number on their html page they graciously present to you will go unchanged. It s not a new phenomenon, every bank does it, except crypto.com does it to pay losses for a theft while banks would do it to lend to a baker buying a bakery on mortgage. If said baker screws up and cant repay, and many more others as well, clients cant all withdraw the pretty number.
Another interesting difference is that a bank pays you for lending to them with your savings account, at market rate (very low these days), while I dont think crypto ponzis do because you re suppose to just wait and moon.
If you re retiring and expect the bank to be good on a million $ worth of some sort of instrument, you're fucked minus 250k.
And this is totally fine: you re compensated for a low risk of default when you lend to your "savings account" and must accept this could happen. There s no way to make money waiting doing nothing risklessly. Creeptards know that well, they all in on wind, there s no worse risk.
As an example, take Bernie Madoff. He took in people's cash and then sent them regular statements about how much money they had. But they were just statements doctored to look good. When some people withdrew money, he just gave them money that was handy. At some point, the difference between the numbers on the statements and the actual assets was over $50 billion. More details here: https://en.wikipedia.org/wiki/Madoff_investment_scandal
None of the Madoff investors "allowed" it. I don't know anything about Crypto.com, but the same thing is surely happening with other "crypto" companies. It doesn't even have to be malice; often a failure starts out with some event like a sudden loss to theft. Insiders believe they can make the money back, so they just keep on operating and hope nobody notices.
This opportunity for divergence between reported and actual funds is one of the big reasons US banks are highly regulated. The FDIC is on the hook for large sums in the event of failures, so they're quite vigorous in making making sure that doesn't happen too often.
[1] https://www.reuters.com/article/us-bitfinex-hacked-hongkong/...
Yes, they do.
> Banks have insurance policies, both private and federal, that would cover the losses.
The federal insurance policy covers you if, after operating this way (or for some other reason) the bank ends up without money to cover your account (and, the regulation that comes with the insurance means that it's more likely that the Federal government will force the sale of your bank to one that does have extra money to cover your account even before that happens.)
But banks still operate as described (and using some of their pool of assets to buy private insurance is functionally the same as just adjusting the balances of people it is compensating for losses and increasing risk to others by doing so, except it smooths things a bit over time at the expense of higher average cost.)
> But banks still operate as described (and using some of their pool of assets to buy private insurance is functionally the same as just adjusting the balances of people it is compensating for losses and increasing risk to others by doing so, except it smooths things a bit over time at the expense of higher average cost.)
It's really not. Customer deposits are segregated from the operating accounts in accordance with applicable law. You're not suggesting they're taking payroll out of customer deposits are you?
Banks don't keep money segregated in accounts.
Banks have reserves, and accounts basically record the right of people to draw money.
When they cover a fraud loss from one account by increasing the balance for that account to make the owner whole, they are doing exactly what crypto.com would be doing. Neither involves taking balances from others accounts, but both increase the risk of inability to cover accounts (including those of other people) as a result. Now, yes, banks provide consumers with more protection against the risk this creates, and are regulated in ways which make them less likely to do it to an extent which would create as much risk as a hype driven crypto exchange in the first place, but in terms of the basic mechanics, it is not any different than what has been suggested.
The model of money actually being held segregated in an account works for things like lawyers holding client funds and a very few other specific things, but it doesn't really capture what goes on with banks at all.
They're...not going to ask your permission?
If you have an account there, they have a large central pile of assets, and a database row saying that you are entitled to X amount of those assets. Someone else has a database row saying that they are entitled to Y amount of those assets.
If someone breaks into the other account, and makes an illicit transfer, then Y goes down and the central pile of assets goes down. If crypto.com makes the other account whole, they simply increase Y back to the original amount. But the central pile of assets hasn't gone up accordingly. They just used "your money" to cover this, and they don't ask you for permission.
When you go to them later and say: "I want to withdraw my X somewhere else", they might say: "I'm sorry, we don't have X right now". That's a run on the bank.
Fortunately, we have protections around specific institutions to prevent these kinds of situations. Capitalization requirements, FDIC, etc. Unfortunately, if you have an account with crypto.com, none of those protections exist for you. You're banking on them having the funds when you ask to withdraw them.
Once it enters their hands, the money isn't really “from” a particular account in any tangible way.
> If i had a account there, i wouldn't allow them to use my money to cover this.
An account is just a record of funds to which you are entitled; there are certain types of relations where someone keeping money for you legally needs to keep it segregated from other funds of theirs, but crypto.com doesn't have that kind of relationship with account holders. If they don't provide you with your funds when you ask, you can try legal action to recover it, but you don't have a veto on whether they update the entry recording someone else's balance to make them whole after a hack, even if that increases the risk that they won't have your money when you want to withdraw it.
So does a normal PC count as a jailbroken device? If not, what makes having root access on a phone any different?
Why lead with the ponzi assumption? There are so many more quantifiable assumptions
For context, this is the startup that has been using Matt Damon as it’s face.
https://www.cryptovantage.com/news/opinion-the-crypto-com-mc...
I'd assume any attacker would at least transfer everything to a BTC/whatever address generated offline, then figure out later how to launder it.
Check out their code on github.
But I'm on record as being in favor of full financial transparency for everybody. Every charge, every bank statement. Money, after all, is inherently social. And full transparency, while causing some problems, would eliminate a ton of others. So if you can get a legislator to submit a bill, I'll happy call them up to back it.
There are plenty of examples of that: https://github.com/jlopp/physical-bitcoin-attacks
Since zero-knowledge cryptography is used to ensure the generated note cannot be linked to the depositing transaction, it can be used to send money to yourself or another person without revealing the identity of the sender. There are criminal and non-criminal reasons to do this.
Because it is a smart contract system, you do not have to trust a person or organization with the money. You do have to trust the smart contracts defining the system are correct. The smart contracts are publicly available to read and have been reviewed by many people, including software audit organizations.
To expand on that, say someone withdraws ETH from Tornado cash and purchases an NFT with it. The seller of the NFT then swaps their ETH for USDC on a decentralized exchange (the ETH then goes into a pool). Later, a liquidity provider to the ETH/USDC pool withdraws liquidity from that pool, and sends their ETH to an exchange, let's say Binance. If Binance blocked such deposits (and especially if they did so without refunding the user on-chain), no one would use Binance, and they'd also be the target of a lot of lawsuits.
The compliance topic is tricky and deceptive. Only the user with a "Note" is able to link deposit and withdrawal. With this note the user can generate a proof of origin. This makes tornado cash compliant enough.
E.G. If the withdrawal address is under Money laundry suspicion, it may be urged to provide the origin of the transaction. That is possible [1] but there is no way of a 3rd party to Tag an account as "suspicious" based on the Tornado chain information (due to the obfuscation done by the Nodes that are getting the fees).
As far as I understand there is no accountability. The regulators would have to persecute all the nodes for helping out with the laundry. But there is no way for the nodes to know they're participating in laundry. So they cant be persecuted. Regulations needs to be invented for this kind of schema.
Please someone correct me if I said anything wrong. Im not an expert is just my conclusion based on some reading.
They're also notable lately for getting the naming rights to the (former) Staples Center.
I mostly agree on the gambling front too - gambling was bad enough when you had to lure people to a casino but at least that gave them the excuse of "It's my form of entertainment, it's like going to a nightclub."
"The best minds of my generation are thinking about how to make people click ads" -- not any more! Now they're trying to find the shortest distance between users' wallets and their RSUs. On the plus side, they can use all of the targeting and persuasion techniques that have been used to make TikTok/Instagram so addictive on directly separating users from their money. Forget selling a product!
For some historic context, Enron Field lasted two seasons and CMGI Field less than one, from what I can tell? I wonder who holds the record.
Since about 2018, VC game changed - now it's about brazenly placing massive bets on a small set of startups of increasingly questionable utility, using the funds and clout to ram their way through into monopoly positions. Not a speck of morality involved anymore - and nobody is even trying to pretend otherwise
Public image hasn't yet caught up with this reality
I think "everybody" here is a pretty substantial overstatement. Plenty of folks were just trying to make money, without much regard for whether it made the world better or worse.
have you actually met any VCs?
I doubt it's very cheap to advertise in F1. You need to outbid large competitors.
https://web.archive.org/web/20170611024100/http://www.crypto...
Attackers care a lot about what they can get to if they are able to breach your security.
(In fact, I have yet to see a single genuine use case for cryptocurrencies or blockchain that aren't served at least as well by more proven technologies, aside from "separating money from fools" and "making libertarians/anarchocapitalists squee".)
Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?
That's why attackers never go after credit card numbers, right?
I think non-revertible payments do not really make a big difference to attackers, it just makes value extraction more efficient. Some percentage of fraudulent transactions will always make it through. So long as the funds accessible to the attacker are sufficiently large, it's still a juicy target. 10% of 200 megadollars is still 20 megadollars.
I agree with @capableweb2. They're an attractive target because they are a financial company with control over lots of value, not because of anything to do with cryptocurrencies in particular.
For most finance companies, if they have a whoopsie and lose money to a software boo-boo, they'll just reverse the transaction. Times when such a transaction cannot be reversed (https://www.bloomberg.com/news/articles/2021-03-19/citigroup...) are the extremely rare exception, and are adjudicated by a civil court.
Whereas if a crypto company has their wallets breached, it's almost certainly immediately irreversible.
Edit: For the downvotes, if this is such an obvious question then be proactive and share the metrics - I'm skeptical this is the case but happy to be proved wrong.
SMB vs. web3/Defi, 30 person teams, no security engineers? The web3 company probably is a lot more vulnerable.
SMB/startup vs. generic crypto exchange like Poloniex? This gets harder to parse. Poloniex gets the malicious traffic and has a pretty small security team I think. But, they and companies similar are a tech company in the cloud and with a solid infra engineering team and leveraging AWS tooling, it's not like they're totally exposed. The SMB/startup has none of this, so arguably they are a similar risk profile in surprising ways, or maybe even more exposed than the exchange.
SMB/startup vs. a Tier 1 exchange like Coinbase? Very silly comparison, CB has a pretty large security team, knows their stuff, etc. etc, very good track record until very recently, and as a industry group the Tier 1 exchanges do well on the security front.
Compare this to the SMB instances of malware sitting on a Point-of-sale system for months/years until it gets discovered? Family dentists getting ransomwared fairly consistently? The retail/SMB space is a bit of a security nightmare. For someone building a product here and is able to sell the "so what" of it to a dentist, there's opportunity. If SMB == startup, well that's likely a startup with 10 hires, extremely product focused, especially with fintech integrations, and presumably a lot of PII as an insurance fintech? If a consultant isn't explaining the fairly large inherent risks there for the SMB/startup and using crypto as a comparison of something worse, that's wonky to me.
If you're auditing startup insurance fintechs in that case, the PII they have and platform exposure to all the APIs they are pulling from or pushing too (a) looks a lot like a crypto company spanning web2/web3, and (b) puts them square in the target of software supply chain hacks. An attacker cares about <insurance startup>, but they do care about attacking the Equifax API that the insurance startup has an integration with. Excluding the crypto companies that do their own custody or run their own smart contracts, their risk profile and why ends up looking a lot like the fintech insurance startup haha.
Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability.
Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind)
But in the real world, if you use a crypto exchange in a reasonable location (e.g. US exchange adhering to US laws) then small thefts like this are going to be reimbursed one way or another.
Now if the entire exchange and their cold wallets were stolen somehow, it would be game over.
But that’s about it. It’s basically another game to play with new financial assets printed out of thin air.
This is because liquidity is the ability to quickly trade your thing for other things. Lending money via a certificate of deposit reduces liquidity because you are locking up your funds. Lending via demand deposits increases liquidity because the original deposit and the loan are both available to be spent immediately. Spending money on physical things is very time consuming. First you must pick what you want to buy among billions of product choices that are available to you. Even if you buy something, it takes time to drive to the store or for it to be delivered. The real world is quite illiquid which means that fiat currency is less volatile and has greater stability than Bitcoin.
Now there are two exceptions. Trading money vs financial assets and money vs other money. In the financial sector you are trading liquidity for liquidity. Buying an iPhone and selling it takes time. Buying Bitcoin and selling it does not. It can happen as quickly as technology allows it. This inevitably leads to speculation because it is possible to instantly react to any other transaction. Someone buys Bitcoin? Buy more! Someone sells Bitcoin? Sell!
To be more specific, the problem isn't liquidity itself but excessive amounts of liquidity that go way beyond what the real economy needs. This is a huge problem with fiat currency but it's also a problem with Bitcoin because the "Bitcoin economy" is absolutely tiny.
Blockchains could, maybe, provide an interesting global platform for fintech to migrate cross-border stuff to. That stuff is not reliable, the engineers are just hella talented
That isn't the technical solution I was looking for...
But you know what I am going to say if you're storing your crypto life-savings or JPEGs on an exchange:
Not your keys, Not your coins and certainly not your NFTs.Since it is across multiple currencies, I think it is unlikely it has to do with generation. Maybe could still be a leak or something.
They'd just pop it in any wallet and sign withdrawal transactions.
There's no 2FA or whitelisted withdrawal addresses (for most tokens) or emails on-chain.
> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure.
> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect.
- abuse the logic flow and simply don’t submit the 2FA step
- submit an empty 2FA token (I’ve seen it work)
- get a signed transaction from a legitimate transfer and replay it in a compromised account
- find the admin API that their help desk uses that doesn’t require 2FA
- brute force 2FA code. If you get 3x attempts at a 6-digit pin you have a 1/333,333 chance. Multiply by a few thousand accounts you can find reused creds for
- Find an API to abuse to disable 2FA (maybe via CSRF?)
- move the money into an account that doesn’t require 2FA (some kind of whitelisted arbitrage account maybe?) then cash out from there
- keep transfers under a 2FA threshold but then either script up the transfer to repeat or change the transfer amount after the threshold check has occurred
I could riff on for ages. Some more plausible than others. Some I’ve definitely seen (and used in legal testing)
I sometimes find it hard to believe these statements, but I guess I can only take them at face value.
Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?".
For better or for worse, a lot of insight can be gained from a sudden influx of tickets from normally-quiet users, all with the same general story. This is definitely how many critical bugs in production are caught, because even a small number of disparate users that suddenly write in about the same issue is a huge red flag.
But, most likely, they have metrics on average withdrawal amounts, deposit amounts, etc., hooked up to something like datadog, with an off-the-shelf anomaly detection monitor.
How are we estimating the likelihood here? I agree that would be desirable. I agree a very together company might have something like that. But given the average level of competence and professionalism in the cryptocurrency sector [1], I would not bet against EMM_386's theory in this case.
[1] See, e.g., https://web3isgoinggreat.com/ or https://bravenewcoin.com/insights/36-bitcoin-exchanges-that-...
How am I supposed to read it: is it a 2FA compromise (attacker replaced 2FA codes with their own) or 2FA bypass (attacker found a way to conduct a transaction bypassing a need for 2FA)? These are two very different scenarios.
This may be their only risk monitoring system. I’ve seen many DR plans that had this kind of detail written up in “consultant speak” with a straight face. Where they would detect server crashes by users calling them and their systematic method to failover was to manually rebuild.
So their monitoring is smarter than their main application? Wow, just wow.
Why do you think everything tends to centralize? To keep things localizable.
...Until that backfires anyway. Thank you 2008.
Can someone setup, test and rollout a _completely new_ authentication system in 3 days?
> A photo of you holding a paper with the following handwritten on it, as it states in this FAQ. - Your name - Today's Date - "Crypto.com”
src: https://help.crypto.com/en/articles/3640569-how-to-close-cry...
…
Act II: thousands of men and women sign up to be brave with semi-retired Jason Bourne.
…
Act III: “we regret to inform you that our security protocols are a disaster”.
I hope not, if that is true.
The year is 2022 and companies managing >$100B in assets are STILL using SMS 2FA for protecting their life savings, despite SIM hijacking and SIM swapping still about.
Quite pathetic really.
There is absolutely no way my parents could figure out 2fa in any way other than phone call/sms. They would be cutting out the less technical crowd, which is exactly who they're trying to convince to buy in
I like how when my credit card gets a fraudulent transaction, all I have to do is push a button on my phone and it magically goes away. This is a major, major benefit of having a central authority.
Its a human coordination mechanism that forces other humans to make it increasingly more resilient when under pressure.
It is Machiavellian with no evolutionary dead ends, just mutating and hardening due to the needs of all of its ever growing participants. Rapid market based iteration on steroids.
The difference is what was centralised is now decentralised, what was implicit and required trust is now explicit and requires formal verification.
> with enhancements we’ve made to our security infrastructure and the introduction of the Worldwide Account Protection Program.
Edit: the funny thing for me is that if the ad ended with the SpaceX (or Boeing, or Northrop, or USAF) logo and gave the SpaceX employment site at the end, I'm sure it would be seen as one of the best ads of the last few years. The leap is what kills it.
The community ethos and ideas seem pretty disconnected from what actually happens.
Remember, not your keys, not your coins!
That's par for the course in the cryptocurrency space. Why develop good technology with well-defined valuable use cases when you can hype your rocketship to the moon?
What does this mean? Does MFA means xFA for x > 2?
I’ve got long term investment accounts that I hardly touch … I would have no problem with such a rule/ extra validation of any moves of money.
Granted crypto.com might not be / want to operate like that.
That said, there is no waiting period on me withdrawing from my checking account.
Ethereum seems to be the token most prized during a breach, most likely to be used on tornado.cash.
Cheers
Get someone to load up and maintain a whole blockchain on their 1TB phone, and you lose them the moment they need more room for photos or offline synced music and files.
A pruned full node downloads and validated all blocks, then discard everything not relevant to its own wallet.
A variety of “light clients” are also available for most chains, which fetch transaction data from peers as needed (usually using something like bloom filters to increase privacy).
Most ethereum apps just go through Infura. That’s a horrible centralized single point of failure that I’m not advocating, but the point is there are many ways a wallet app can connect to a remote full node.
(and missed out on settlement too! and domain name apparently is being re-used, ugh)
Nah... Probably never catch on.
We all have our price.
Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
I believe in bitcoin, works well and I don't blame the consumer for the producer's problems when it comes to power.
But exchanges have become a key part of the implementation.
That's not the real issue though. The issue is the _need_ for exchanges. They provide a host of services, mostly all of which are antithetical to the loftier ideals espoused by bitcoin.
Too many crypto fans waltz passed this glaringly obvious issue and these kinds of stories will never go away as a result.
If banks get hacked, nobody blames the internet. "a small sub section of the system" applies as aptly to the blockchain as it does the global financial system, and I'm pretty confident being a locally popular trading commodity amongst edge communities is not the central goal for bitcoin
Given the transaction fees needed for a distributed-enough network, and the bureaucracy needed when trading, it is not very useful as a currency, at least not for small payments, excluding Lightning.
So it's a commodity.
Do you consider a website breaking a single point of failure for the internet?
Or put another way, how does Crypto.com and other centralized systems prevent me from using Bitcoin the "right" way?
You can point to centralized products built on top of blockchain, but also decentralized ones.
I think you may be forgetting, earlier users of computers were using punchcards..
But in brief my point is that as with internet itself, a protocol that allows for decentralization is not sufficient for something to be truly decentralized. Despite the vast amounts of hype about the decentralization of cryptocurrency and "web3", in practice we are seeing that it's tending toward centralization. Which personally I don't care about except the extent to which I still have to listen to the hype that has less and less connection to the practical reality.
But yes, I would agree that banks are about as decentralized as crypto exchanges. But that's kind of the point, you shouldn't conflate exchanges (or banks) with the currency itself.
Have you considered that you are in the wrong decade? Its year .. 13..? Its time to be up to speed on this.
If you run into a proponent that is also conflating these things you should simply correct them about the difference between onchain activities and third party centralized service providers, which means educating yourself first.
The only reason the hacker gets to keep the funds and have no civil or criminal liability is because of them using the actual decentralized rails and uncensorable contracts such as Tornado.cash