0%

Tips on how to best secure your crypto

2021년 6월 9일 5 분 읽기
뉴스 기사 배너 이미지

When someone is able to log into one of your accounts to perform fraudulent activity, this is called an “account takeover”, or “ATO” for short. But how do these fraudsters get into your account in the first place? One common method is called a “SIM-swap.” In a SIM-swap attack, fraudsters will actually contact your wireless carrier pretending to be you, and persuade the customer service agent to redirect your cell service to a different device, by changing the SIM card number associated with your account (hence the name of the attack.) Once they succeed, they are able to receive all calls and SMS messages sent to your phone number — including any two-factor authentication codes sent to you via SMS. From there, fraudsters will frequently pair those SMS 2FA codes with stolen passwords to try and log into your email account, social media profiles, cloud storage accounts like Dropbox, or financial accounts like Coinbase.

At Coinbase, we do a lot of work behind the scenes to detect and try to stop SIM-swap ATOs targeting our customers’ accounts. We also believe that using SMS-based two-factor authentication (2FA) is better than using no 2FA at all. That said, we encourage everyone to follow the two simple steps below and apply them to all the accounts they care about — not just their Coinbase accounts.

Use a password manager

  • Your passwords should be at least 16 characters, extremely complex and unique for your accounts. That’s hard to do by yourself, but password managers like 1Password or Dashlane can be used to create and remember your passwords.

Are you currently using a password that has been exposed in a third-party data breach somewhere? You can check to see if you’re using a risky password by visiting haveibeenpwned.com/Passwords .

Use 2-factor authentication (2FA)

  • In addition to strong passwords, where available, use two-factor authentication (2FA). And always use the strongest type of 2FA the platform allows, ideally a Yubikey or similar hardware security key.

  • If a service provider doesn’t allow Yubikey, use an authentication app like Google Authenticator or Duo Security instead of SMS-based 2FA if possible.

  • If SMS-based 2FA is the only thing available, at the very least require a one-time 2FA code sent to your device every time you login so someone can’t access your account if they have stolen your password.

  • If an organization doesn’t offer any of these options, consider not using that service.

Staying vigilant in the wild

It’s not only important to play defense with the right security tools when protecting your accounts, but it’s also important to stay smart in the wild.

Some guidelines:

Don’t make yourself a target

  • Don’t brag about your cryptocurrency holdings online, just like you wouldn’t advertise inheriting $50 million.

  • Review your online presence and see how much personal information someone could learn about you to steal your identity. (The good folks at Consumer Reports put together this self assessment.)

Don’t fall for tricks

  • Hackers posing as tech support — even bad actors posing as Coinbase customer support specifically — may pressure you for account credentials. Coinbase will never ask you for passwords, 2FA codes, PIN numbers or for remote access to your computer.

  • Coinbase will never ask you to create test accounts on other platforms or provide your ID or banking information over email or social media. We do not offer Facebook support chat and we will never call you by phone.

  • If someone reaches out to you and you’re not sure if it’s a scam, you can reach out to [email protected] to confirm whether it’s legitimate. And remember, Microsoft, Google, and Apple will never call you about your computer.

Check the URL

  • Scammers create fake sites that look like real exchanges but are designed to steal account information. Double check the web address before you login into your account or input any of your credentials.

  • If we emailed you and include a link, copy the link and paste it into a text editor before entering it into your browser to make sure you know where the link is really taking you.

This phishing domain uses an Internationalized Domain Name (IDN) which closely resembles www.coinbase.com. However, looking closer will reveal that the domain is actually www.coįnbase[.]com (note the character accent below the “i”).

While Coinbase has gone to great lengths to secure our environment, it’s important that everyone understands their role in maintaining the security chain. By following some basic security steps, you can make sure your crypto stays safe. To learn more, visit our Help Center.

was originally published in The Coinbase Blog on Medium, where people are continuing the conversation by highlighting and responding to this story.

인기 뉴스

How to Set Up and Use Trust Wallet for Binance Smart Chain
#Bitcoin#Bitcoins#Config+2 더 많은 태그

How to Set Up and Use Trust Wallet for Binance Smart Chain

Your Essential Guide To Binance Leveraged Tokens

Your Essential Guide To Binance Leveraged Tokens

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)
#Subscriptions

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)

What is Grid Trading? (A Crypto-Futures Guide)

What is Grid Trading? (A Crypto-Futures Guide)

Cryptohopper에서 무료로 거래를 시작하세요!

무료 사용 - 신용카드 필요 없음

시작하기
Cryptohopper appCryptohopper app

면책 조항: Cryptohopper는 규제 기관이 아닙니다. 암호화폐 봇 거래에는 상당한 위험이 수반되며 과거 실적이 미래 결과를 보장하지 않습니다. 제품 스크린샷에 표시된 수익은 설명용이며 과장된 것일 수 있습니다. 봇 거래는 충분한 지식이 있거나 자격을 갖춘 재무 고문의 조언을 구한 경우에만 참여하세요. Cryptohopper는 어떠한 경우에도 (a) 당사 소프트웨어와 관련된 거래로 인해, 그로 인해 또는 이와 관련하여 발생하는 손실 또는 손해의 전부 또는 일부 또는 (b) 직접, 간접, 특별, 결과적 또는 부수적 손해에 대해 개인 또는 단체에 대한 어떠한 책임도 지지 않습니다. Cryptohopper 소셜 트레이딩 플랫폼에서 제공되는 콘텐츠는 Cryptohopper 커뮤니티 회원이 생성한 것이며 Cryptohopper 또는 그것을 대신한 조언이나 추천으로 구성되지 않는다는 점에 유의하시기 바랍니다. 마켓플레이스에 표시된 수익은 향후 결과를 나타내지 않습니다. Cryptohopper의 서비스를 사용함으로써 귀하는 암호화폐 거래와 관련된 내재적 위험을 인정하고 수락하며 발생하는 모든 책임이나 손실로부터 Cryptohopper를 면책하는 데 동의합니다. 당사의 소프트웨어를 사용하거나 거래 활동에 참여하기 전에 당사의 서비스 약관 및 위험 공개 정책을 검토하고 이해하는 것이 필수적입니다. 특정 상황에 따른 맞춤형 조언은 법률 및 재무 전문가와 상담하시기 바랍니다.

©2017 - 2024 저작권: Cryptohopper™ - 판권 소유.