4 ms·
yes, they literally logged everyone out, removed 2FA, and on the new login, users had to re-add 2FA
by presty 5y ago
yes, they literally logged everyone out, removed 2FA, and on the new login, users had to re-add 2FA
- cornedor 5y agoWouldn't this also allow an attacker to add his own 2FA?
- Scoundreller 5y agoDoesn’t really matter if your 2FA keygen algo got completely compromised.
- mdoms 5y agoOf course it matters. Even if we assume someone figured out how to own the 2FA system, that knowledge doesn't magically make its way into the brain of every script kiddy capable of credential stuffing a login form. They're two totally different vectors with different surface area.
- Scoundreller 5y agoMy thought is that it’s not really 2FA, and 2FA means temporary tokens, and there’s a method to gain entry with just login+token, e.g. via password reset.
- tialaramex 5y agoYou can just make up whatever factors. If you want to deliver security then MFA is an interesting strategy that needs careful consideration and planning, you might end up building things like Security Keys so as to solve real threats. You might fix real problems (Google eliminated phishing) at your organisation. But if your goal is to bamboozle fools into giving you their real money in exchange for Itchy and Scratchy money that you may or may not then "lose" then you don't need all that hard work. Take whatever nonsense you cobbled together and say it's "Two factor" because that means "good" to people who don't know any better.
- nefitty 5y agoThis is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
- barkingcat 5y agoI'd say Coinbase is the company at the apex of the US cryptocurrency industry. crypto.com is a two bit player in comparison.
- rmbyrro 5y agoIsn't this equivalent to saying the entire health industry is fake and untrustworthy because of Theranos? I don't it looks kind of same to me, and sounds absurd.
- capableweb 5y agoCalling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.
- smt88 5y agoAren't they one of the largest exchanges? EDIT: They're #3 (bigger than Coinbase). Only OKX and Binance are bigger[1]. 1. https://www.coingecko.com/en/exchanges https://www.coingecko.com/en/exchanges
- barkingcat 5y agoNo! Coinbase is a large exchange...
- thebean11 5y ago
- eswat 5y ago> users had to re-add 2FA And you are not asked to do this while logging in again. It is assumed you know why you have to reauthenticate and that you have to re-add 2FA in your app settings…