Hacker News new | ask | show | jobs
by tcarey83 4455 days ago
I was phished for coinbase just recently with an email telling me "You just received 0.08525920 BTC" and just "Click here to sign in and view this transaction" and I stupidly I did click on the link and did try to log in. The login failed (as it would with a trojan and the coinbase 2 factor authentication I have enabled). But even so, the phishing site was able to attach 3 Android apps to my account with full access. I deleted the apps and notified coinbase, but they were totally less than helpful.
1 comments

People should upvote this much more. This shows that the reported exposure has resulted in at least one successful phishing.

The fact that the 2 factor auth can apparently be bypassed by attaching apps is another security vulnerability entirely. If that is what you are claiming is the case, then they should be immediately fixing this as soon as you reported it to them.