firstamendment avatar

stop using yahoo mail for crypto and stop using coinbase

firstamendment

Published: 03 Aug 2021 › Updated: 03 Aug 2021stop using yahoo mail for crypto and stop using coinbase

stop using yahoo mail for crypto and stop using coinbase

About a month ago I was hacked, and I got hacked pretty hard but not financially. They stole my phone number, logged into my yahoo account, and ran a script to password reset just about every account I had tied to it. They stole some freebies from coinbase, and took an even smaller amount on a small exchange I use. It only took a few hours for the attackers to steal the crypto from logging into a new devise, despite coinbases password reset policy which is the standard 24 hours. 24 hours isn't much; I used to spend 16 hours a day going to, at, or coming back from the university a day+time you consider sleep-the 24 hour freeze offers little to no protection at all. Also plenty of folks who hardly ever use their phone & email. Needless to say my bittrex account was more secure than sms 2fa, but they still let the attacker change my password. Gemini froze my account luckily.

The attacker was using a mullvad vpn, and mullvad claims not to log ip addresses and they are a swiss based company. So pretty much filing a police report does no good. I chewed out coinbase; how could they violate their TOS, how could they let a user into my account on a vpn, how could let let a user log in in Montreal one moment then 2 hours later let them log on in Atlanta some 1200 miles away. The response from coinbase has been to ignore the issue, and let the hacker steal about $6000 of eth based tokens from users...and maybe closer to 40k between tokens and eth.

One thing I learned from this is not to use SNS based 2fa. Upgrade them to google authenticator-at a minimum-if possible.

So I closed out my bank account to prevent unauthorized wiring of money. Last month I got a brand new phone, and new phone number to start securing my accounts better and to be separated from yahoo. Only I could not register the product nor get the software to work without registering it, so it has been sitting on the sideline. So needless to say I get a call this morning that I was hacked...again. Not this again. But luckily I stepped up security from last time. My coinbase account remains frozen from last month, but lo and behold I get emails saying that someone changed my ip address....from a mullvad based VPN. So they literally had a month to block mullvad ip addresses after being put on notice. So not only do they not follow their own security policy on password reset, they also refuse to close known security vulnerabilities.

So this morning I was kind of more prepared than last month. My important accounts were secure. So I called my phone provider to get my phone # back, before commencing rescues,and to see if they got in through a web portal. Turns out the attackers were calling just the phone representative to transfer my phone number to them. Social engineering, from likely another stolen phone number.

I also go through my yahoo account, which just had a nice password reset a month ago to something very unique. Still they got in, something called "Signed in using phone verification". So something was off. Was there a session hijacking which triggered a 2fa, did someone have remote/viral access to my pc, did someone answer my recover questions, did someone hack my recovery account, was there an "account key" back door. How did this happen? I needed to know so I could secure my account. So I called yahoo's number. They initially thought it was coming from the recovery email address, but then they also noted that it wasn't the case because they got in through a phone. What happens is if you mess up on your password enough times, a text message gets sent to the phone. Ultimately, if an attacker knows there is a phone number attached to your yahoo email address, all they need do is steal your phone number to gain access. Just through social engineering; it's like you have no password at all guarding your crypto. The code they send to your phone number on their phone is all [possibly the 2fa also which ordinarily is codes sent to that phone] they need to get in. Yahoo doesn't offer any extra tools to block users from VPNs from accessing accounts.

Supposedly Yahoo was supposed to rolled out google 2fa back on july 6th which could keep the attacker out if they stole my phone # again, but after checking a few devices and browsers it turns out it wasn't rolled out yet. I'm Not sure when that will be rolled out, but until then if you have a recovery phone number on your yahoo account you are at great risk.

A big company like coinbase, yahoo, gemini, bittrex, ought to allow users to block vpns by default [unless account created through vpn]. There are legitimate uses for VPNs, but outside of these special use cases, companies need to treat them with aggressive hostility. I remember rolling out my social media platform and being hit by spam bots. First thing I did was block the bad ip addresses, blocked guest users [who weren't supposed to be there anyways], and added capchas for users to log in. That isn't a viable solution for say universities, and hence the need to develop intelligence systems to block certain patterns of abuse. But it seems along that way, VPN security vulnerabilities has been ignored by bigtech in favor off algorithms. Now there are online services that supposedly detect if an ip address uses a vpn, but I can understand for privacy reason a company may not want to shed that kind of info to a 3rd party vendor. But still, you can freaking get interns for free to hunt down vpns, put them in a csv , the source of info, and hand them to a chief security officers to process through an algorithm. I'm Pretty sure that will save hours of customer service and even prevent costly litigation.

Sure they could go to say a university, a coffee shop, a macdonalds, etc, as an alternative to a VPN. But if they do that, you pretty much know the attackers real location, and they might even show up on video somewhere. Establishing identity is legally very important. Sure, maybe they'll try to control a zombie net, but the attackers don't sound that sophisticated. Their script is, but the attackers seem amateur for now.

I have been able to trace some of the attackers crypto to a certain eth address.

https://etherscan.io/address/0x544d75cA25DD1c051A4864dFFdd271D94fc5752C#tokentxns

The holder of the keys sent the crypto to kucoin. I asked kucoin them to freeze the account and check with coinbase security, they adamantly refused and needed law enforcement or a court order. claiming it was about protected a users assets. Since when does freezing assets steal assets; how does that breach the duty of a fiduciary? I been meaning to swear out a criminal search warrant myself (F___ the police; let's take power back from them), but I don't presently have meaningful physical access to the courts; I emailed the clerk about electronically filing an affidavit for a search warrant; Silence. I could similarly file a subpoena if I do a small claims against coinbase, but it takes such a long time. I think with a court order that I might just end up with a name and photo of another one of their victims. I know what I can do to at least get geographic information on the attackers.

Anyways, it seems the attacker has stolen at least $27k+ worth of crypto. https://etherscan.io/address/0x544d75cA25DD1c051A4864dFFdd271D94fc5752C But pretty much my gut feeling is, especially with coinbase who violates their own password reset policies to let attackers insta-drain an account, is that they are knowing and willing participants is money laundering. It is really one of the few ways that crypto held in the KYC realm gets converted back into anonymous crypto. It can still be tracked, but they aren't interested in stopping it unless the breach earned mega clout status.

Pretty much the responses I received from most exchanges about the issue is, please we want you to trade with us [and we refuse to listen to your concerns about security holes]. They can't even assured me that they haven't taken appropriate steps to stop this attack vector.

Leave stop using yahoo mail for crypto and stop using coinbase to:

Written by

Hive is not a place for free speech, you have a social credit score that destroys your reputation and could hide your posts-and push you back to traditional social media. When someone using the name first amendment has to tell you that, having been chased off on the irrational whims of the gatekeepers, you know things are bad. Consider also that one of the main whales, a Dan Notestein, operates a non-profit called peer verity that seems to be some kind of censorship tool. So when you hear that Hive/block chain is a place for free speech, don't believe it. The audience you'll find off chain is larger than you'll ever find on chain, I'v steer national debates countless times across all media platforms multiple times-including top network Tv stations and the international press. You can't do that in w3, the ecosystem doesn't support that yet-and at the present moment x, or twitter, on w2 has the present dynamics. On hive, You are a tree in a forest, on some deserted island thousands of miles from anywhere-and hive watchers, or should we say valueplan, don't want anyone on the mainland know we exist. If you want to be heard, You have to know something about how the media business works-and they are not here. So whether you make a quarter on hive for a post, or your self-vote is worth hundreds of dollars, nothing you say here will ever be deemed important at the present dynamics. Valueplan can spend millions of dollars for marketing to attract tourist to this island, only for their tourist to step in a steemy pile of bull s___, and be served that same pile of s__ for dinner, and leave telling others how bad the experience was. You believed in hive and its potential, but the governance and their censorship arm doesn't believe in you-they'll even destroy entire communities just because the community leaders were trying to tolkenize developing a community here, when there is hardly anyone left anyways. They are not thankful people use this platform, they are actively hostile to it. The dynamics of hive governance has to change if it is to have a future, otherwise you are wasting your time-and money. Many of those behind hive governance got into crypto early effectively winning the lottery, many were part of a prior chain called bitshares, and were part if the notorious ninjamining about a decade ago. In essence they hit the lottery and have money and power, they don't know how to operate a business to the public, and despite having no merit they think they are better than you. They already destroyed bit shares, hive is next if they remain in control. This same team is behind valueplan, responsible for attracting new users-or so they claim. Since they exhausted the market in the developed world and started the bright idea of onboarding the third world-which is unlikely to have water, electricty, internet, and disposable income. Nothing against them, but this is not a solid investment plan, something where people are more likely to liquidate the new assets released from the DAO. The average IQ is typically about retarded to put it mildly, so the expectation for them to stake hive dollars and have a stablecoin is laughable, and what to do with them other than to liquidate them below fair market value. It should also be noted that Dan notesteins planned charity on bit shares, that he hates government regulations, and it is fair comment to assume the Value of hive is being destroyed to run''s Dan's charity. While valueplan is full of fraud and waste itself, the bulk of the existing governance is a fraud not interested in developing a community-but in destroying it for their own power or financial gain. I seen the price tank from when hivewatchers targetted me, from 20-40 cents, down to a about dime now. If something happens badly to bitcoin or crypto, particularly a systemic threat to the crypto market (like say the democrats winning an election), or if the current dynamics continue then expect to see further declines. I haven't seen "the Koreans" try to market manipulate the coin in ages, did they lose interest in hive too? You see the whales pretending to care about the bleeding through the dao, particularly with value plan, but they offer nothing of substance to fix it-"they" need the fraud to continue. They are scared they will soon complete the repeat of what they allowed happen to bitshares. Oh, the distinction is we have a hair cut rule. The hair cut rule might prevent infinite coins, but it will not stop the complete devaluation of the chain. Hive will not be saved through the current governance, it's impossible. in time, the core projects will not be funded. A decision will have to be made to fire devs, or shut down mission critical projects-whom we probably don't need devs for anyways, let alone multiple full time devs. There will no tangible reward, and the audience is already pretty much non-existent as they've been scared away. It's not like we can fire the current governance, they are lottery winning ninjaminers. When the coin does go to zero, don't expect them to sell a dead coin-dead coins and dead wallets tend to be forgotten about unless new value is found. Dead coins also tend to be delisted. If someone were to try to save it post apocalypse, these whales would come back to restore the old order. If these accounts become dormant (their bots may continue to up/down vote and post AI/reports) as to allow new interest to take over, the first thing that must be done is to find a legal means of rendering them impotent. Not like Justin sun, but perhaps in the form if an air drop to the remaining active community, or to a central planner who can give the community a new direction.

Read more #hive posts


Best Posts From firstamendment

We have not curated any of firstamendment's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.

More Posts From firstamendment