←back to thread

410 points gpi | 4 comments | | HN request time: 0.748s | source
1. olalonde ◴[] No.44003629[source]
Brian Armstrong (Coinbase CEO) posted a video about this today: https://x.com/brian_armstrong/status/1922967787309256807
replies(1): >>44003790 #
2. koakuma-chan ◴[] No.44003790[source]
"But customer support agents do have access to personal information like name, date of birth, address, et cetera"

Apparently "et cetera" includes photos of my ID? Why do they even keep it?

replies(2): >>44003827 #>>44004156 #
3. cmcaleer ◴[] No.44003827[source]
The more alarming part for me is that, given the scale of the breach, there was clearly some way for this CS access to (a) query and download data from a database and (b) exfil that data in bulk. Where on earth were the controls?
4. olalonde ◴[] No.44004156[source]
They are required to by law (thanks to AML regulations).