←back to thread

410 points gpi | 3 comments | | HN request time: 0.856s | source
Show context
mafriese ◴[] No.44003034[source]
> The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities

Based on the information present in the breach, I think it's likely that the source was their customer support in the Philippines. Monthly salary is usually < 1000$/month (entry-level probably even less than 500$) and a 5000$ bribe could be more than a year worth of money, tax-free. Considering the money you can make with that dataset now, this is just a small investment.

> •Name, address, phone, and email; •Masked Social Security (last 4 digits only); •Masked bank-account numbers and some bank account identifiers; •Government‑ID images (e.g., driver’s license, passport); •Account data (balance snapshots and transaction history); and •Limited corporate data (including documents, training material, and communications available to support agents).

This is every threat actor's dream. Even if you only had email addresses and account balances, this is a nightmare. Instead of blackmailing the company, you can now blackmail each individual user. "Send me 50% of your BTC and I won't publish all of your information on the internet". My guess is that we will have a similar situation like we had with the Vastaamo data breach...

https://en.wikipedia.org/wiki/Vastaamo_data_breach

replies(4): >>44003213 #>>44003459 #>>44003599 #>>44013854 #
lm28469 ◴[] No.44003213[source]
> •Name, address, phone, and email;\

> blackmail each individual user

Blackmail would be the least of my worries, in France we had at least five kidnappings/attempted kidnappings related to crypto investors since the beginning of the year.

replies(3): >>44003282 #>>44003329 #>>44003382 #
stringsandchars ◴[] No.44003382[source]
This may seem callous, but isn't a large point of crypto that you are 'free' from the shackles imposed by the State?

And I guess that includes protection from criminals by the oppressive forces of the State (aka the police). In which case being kidnapped and having your fingers sent to your family is an integral part of your 'freedom'.

replies(8): >>44003398 #>>44003450 #>>44003666 #>>44003691 #>>44003772 #>>44003902 #>>44004223 #>>44005823 #
1. cmcaleer ◴[] No.44003772[source]
This may be surprising, but I actually don't think opting for a payment method with less consumer protections (that I pay cap gains tax on when if I dispose of it for a profit) is me ceding my right to be protected by the police. You're right that it does seem extremely callous and is honestly a disturbing mindset to have. Hopefully you never experience terror like the victims of the last few months in France experienced in your life.
replies(1): >>44003873 #
2. stringsandchars ◴[] No.44003873[source]
> You're right that it does seem extremely callous and is honestly a disturbing mindset to have. Hopefully you never experience terror like the victims of the last few months in France experienced in your life.

Thanks for the tone-policing. But instead of implicitly suggesting that my mindset or tone is inappropriate, it would be great if we discussed the substance of the points.

replies(1): >>44004316 #
3. cmcaleer ◴[] No.44004316[source]
> it would be great if we discussed the substance of the points.

Sure, just read the sentence from my response that you skipped over.

To be clear: I didn't implicitly suggest that your mindset of people who use crypto somehow ceding their right to protection from the state was inappropriate, I stated outright that it was a disturbing and callous mindset.

It's like suggesting that people who protest against police brutality shouldn't get protection from the police in emergency situations, or believe people who are racist to healthcare workers should lose all right to healthcare. The type of mindset held by those who care more about retribution against those who hold different views than a just society.