Warning: session_start(): open(/opt/alt/php72/var/lib/php/session/sess_982c65c8d76a90f65879fdfe444129d4, O_RDWR) failed: Disk quota exceeded (122) in /home/shweuqjw/awajludhianaki.org/wp-content/plugins/jnews-social-login/class.jnews-social-login.php on line 83

Warning: session_start(): Failed to read session data: files (path: /opt/alt/php72/var/lib/php/session) in /home/shweuqjw/awajludhianaki.org/wp-content/plugins/jnews-social-login/class.jnews-social-login.php on line 83
What $10M in daily thefts tells us about crypto security – TechCrunch - Awaj Ludhiana Ki
Sunday, June 8, 2025
  • Home
  • National
  • International
  • Movies
  • Technology
  • Business
  • Fitness
  • Lifestyle
  • Punjab
  • Contact us
No Result
View All Result
No Result
View All Result
Home Technology

What $10M in daily thefts tells us about crypto security – TechCrunch

by author
June 2, 2021
in Technology
0
What $10M in daily thefts tells us about crypto security – TechCrunch
0
SHARES
26
VIEWS
Share on FacebookShare on Twitter


Andrew Shikiar
Contributor

Andrew Shikiar is the executive director and CMO of FIDO Alliance.

If you’re among the growing number of people interested in cryptocurrencies, you may be interested to know that nearly 7,000 people lost more than $80 million between October 2020 and March 2021 — a 1,000% increase from a year ago, according to the Federal Trade Commission.

Related posts

With Wickr purchase, AWS enters the encrypted messaging business – TechCrunch

With Wickr purchase, AWS enters the encrypted messaging business – TechCrunch

June 25, 2021
Mercuryo raises $7.5M for crypto-focused, cross-border payments after crossing $50M in ARR – TechCrunch

Mercuryo raises $7.5M for crypto-focused, cross-border payments after crossing $50M in ARR – TechCrunch

June 25, 2021

The scams include fake currency exchanges and phony “investment” websites selling the currency. More recently, more than $10 million was stolen in various cryptocurrencies in the days leading up to Elon Musk’s appearance on “Saturday Night Live.”

And here’s the rub: You have no way to protect your accounts from any theft. In the world of cryptocurrency, there are no guarantees. Unlike the traditional banking world, there is no equivalent to the Federal Deposit Insurance Corporation to cover any losses on your account. If your assets are stolen, you’re out of luck.

Nearly 7,000 people have lost more than $80 million between October 2020 and March 2021 — a 1,000% increase from a year ago, according to the Federal Trade Commission.

Enabling secure access to these cryptocurrency assets is absolutely critical to preventing theft — which, as of the end of 2020, amounted to just over $10 million a day — and/or lockout of one’s potential fortune.

But how can you ensure that people can always access their accounts? That depends on how the accounts are set up initially — which usually means that passwords or other knowledge-based authentication (KBA) is involved. Unfortunately, passwords simply aren’t suitable for securing high-value accounts because they can be easily compromised, either through phishing attacks or outright theft.

Plus, if you have a less-used cryptocurrency wallet, you might forget your initial password and might have trouble recovering it — if there is even a mechanism to perform the recovery. KBA is also plagued with problems ranging from lack of recollection (what is my favorite hobby again?) to the wide availability of “personal” information on the web (for a few dollars, you can surely find my mother’s maiden name).

Cryptocurrency account takeovers happen with increasing frequency; it doesn’t help that there are few pre-established trust relationships between users and the exchange or wallet provider and that almost all transactions are finalized within minutes and not easily reversible.

Sadly, these takeovers make use of a very similar pattern that has been observed for years in the traditional banking world: An attacker will first try harvesting and then stuffing stolen credentials. If that doesn’t work — say a user has protected their account by requiring an SMS second factor — they will move on to popular techniques to overcome SMS, such as SIM swapping or a $16 SMS relay service that sends that SMS code to the attacker’s smartphone, which leads to a “successful” account takeover.

Even highly secure tokens or dedicated authenticator apps are vulnerable to replay attacks from a motivated hacker — and with personal fortunes at stake, there is no lack of motivation.

Furthermore, the vast growth in the number of cryptocurrency exchange users coupled with this need for strong cybersecurity has resulted in terrible support experiences where users have to wait for weeks or even months to regain access to their own accounts — simply because it is so difficult for them to prove they are the rightful owner.

Authentication best practices can help

So how do we fix this situation? With standards-based user authentication that has been proven to be resistant to phishing and account takeovers — and that is already embedded into billions of devices worldwide and available to just about any user on a modern browser. The FIDO (Fast IDentity Online) authentication protocols were developed by a who’s who of IT, payments and consumer services and ensure that all cryptographic credentials are stored on a user’s device — thereby eliminating even the most advanced machine-in-the-middle attacks.

The crypto exchange Gemini was an early adopter of FIDO for both its smartphone app and for browser users, with a growing percentage of its users protecting their accounts with FIDO authentication by purchasing FIDO Certified security keys. There have been a number of other exchanges that have added FIDO authentication, such as Coinbase, which also supports FIDO keys. Binance has FIDO for its web versions, but not on its smartphone apps yet. And STEX also has support for various FIDO devices and methods. Finally, Ledger hardware wallets support FIDO directly in their devices.

Ideally, it would be better and more effective if there was broad cryptocurrency industry acceptance of FIDO’s approach to modern authentication and adoption of several related best practices, such as:

  • Standardize authentication flows and practices across crypto exchanges. Better user authentication should be a standard practice for every exchange, not a competitive differentiator. If all leading exchanges moved to industry best practices for account creation, login and recovery, it would help protect customers — and their collective crypto assets.
  • Require users to enroll multiple authenticators to help with account recovery for each cryptocurrency exchange, whether that is two FIDO security keys or a FIDO security key and a biometric authenticator. Having multiple account recovery keys for each cryptocurrency exchange will help lessen support burdens and help users who lose a device. It will also offer users a choice of stronger authentication options.
  • Eliminating less secure backup and recovery options, such as using SMS or other knowledge-based authentication factors, will also help improve overall security, particularly for account recovery.

The bottom line is that for the cryptocurrency market to reach its full potential, its exchanges need to collectively strike a balance between the anonymity and privacy that make crypto unique with the security of accounts and assets. Following the lead of crypto exchanges like Gemini and letting users lock down their accounts is a great step toward protecting users against phishing and account takeovers while maintaining privacy and convenience.

Andrew Shikiar is CMO and executive director of The FIDO Alliance, which promotes the development of, use of, and compliance with standards for authentication and device attestation.



Source link

Previous Post

Covid-19: Higher tax benefits expected as employers extend helping hands to employees

Next Post

Smartphone maker OnePlus likely exploring crypto space; asks its 'community' about use of crypto wallets

Related Posts

With Wickr purchase, AWS enters the encrypted messaging business – TechCrunch
Technology

With Wickr purchase, AWS enters the encrypted messaging business – TechCrunch

June 25, 2021
Mercuryo raises $7.5M for crypto-focused, cross-border payments after crossing $50M in ARR – TechCrunch
Technology

Mercuryo raises $7.5M for crypto-focused, cross-border payments after crossing $50M in ARR – TechCrunch

June 25, 2021
Kaszek Ventures leads a $15 million round in Chilean asset management startup, Fintual – TechCrunch
Technology

Kaszek Ventures leads a $15 million round in Chilean asset management startup, Fintual – TechCrunch

June 25, 2021
Kayak co-founder Paul English just launched Moonbeam, a podcast discovery app – TechCrunch
Technology

Kayak co-founder Paul English just launched Moonbeam, a podcast discovery app – TechCrunch

June 25, 2021
Gotrade gets $7M led by LocalGlobe to let investors around the world buy fractional shares of U.S. stocks – TechCrunch
Technology

Gotrade gets $7M led by LocalGlobe to let investors around the world buy fractional shares of U.S. stocks – TechCrunch

June 25, 2021
To sustain diversity, investors must tune into their unconscious biases – TechCrunch
Technology

To sustain diversity, investors must tune into their unconscious biases – TechCrunch

June 24, 2021
Next Post
Smartphone maker OnePlus likely exploring crypto space; asks its ‘community’ about use of crypto wallets

Smartphone maker OnePlus likely exploring crypto space; asks its 'community' about use of crypto wallets

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

US Senator Says Mysterious Drones Spotted In New Jersey Region Should Be ‘Shot Down, If Necessary’ | World News

US Senator Says Mysterious Drones Spotted In New Jersey Region Should Be ‘Shot Down, If Necessary’ | World News

6 months ago
Good Day Defence School: Nurturing India’s Youth with the Values of Discipline, and Leadership | India News

Good Day Defence School: Nurturing India’s Youth with the Values of Discipline, and Leadership | India News

5 months ago
No one will be left behind due to one’s religion: PM Narendra Modi at Aligarh Muslim University centenary celebrations | India News

No one will be left behind due to one’s religion: PM Narendra Modi at Aligarh Muslim University centenary celebrations | India News

4 years ago
India vs England 1st ODI: Hosts face ODI World Champions’ might, focus on Shikhar Dhawan | Cricket News

India vs England 1st ODI: Hosts face ODI World Champions’ might, focus on Shikhar Dhawan | Cricket News

4 years ago

BROWSE BY CATEGORIES

  • Animals
  • Architecture
  • Automobiles
  • Business
  • Culture
  • Fitness
  • International
  • Lifestyle
  • Movies
  • National
  • Sports
  • Technology
  • Travel

BROWSE BY TOPICS

Architecture culture Fitness indian architecture indian culture indian culture and heritage indian news lifestyle national news Technology technology news Travel travelling

About Us

Awaj Ludhiana Ki

Address

2667/3, Kishore Nagar, Tajpur & Jail Road, Ludhiana – 141008

Recent News

  • Indian Astronaut Shubhanshu Shukla Set To Make History With Axiom-4 Mission On June 10 | India News
  • Trump Threatens Federal Action Over LA Unrest, California Governor Pushes Back – What Set Off Tensions? | World News
  • India-UK Ties Strengthen: PM Modi, UK Foreign Secy Discuss Bilateral Cooperation | India News
  • Chhal Kapat: The Deception trailer out: Shriya Pilgaonkar starrer Zee5 show to start streaming from June 6, watch : Bollywood News
  • Indian Navy Set To Induct First Anti-Submarine Shallow Water Warship ‘Arnala’ On June 18 | India News

Category

  • Animals
  • Architecture
  • Automobiles
  • Business
  • Culture
  • Fitness
  • International
  • Lifestyle
  • Movies
  • National
  • Sports
  • Technology
  • Travel

Search

No Result
View All Result

Email

contact@awajludhianaki.org

  • About
  • Advertise
  • Careers

Copyright © 2019 Awaj Ludhiana Ki or it's affiliates | Website by Awaj Ludhiana Ki Team

No Result
View All Result
  • Home
  • Contact us
  • Animals
  • Architecture
  • Automobiles
  • Business
  • Culture
  • Fashion
  • Fitness
  • Food
  • International
  • Lifestyle
  • Movies
  • National
  • Sports
  • Technology
  • Travel
  • Punjab

Copyright © 2019 Awaj Ludhiana Ki or it's affiliates | Website by Awaj Ludhiana Ki Team

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In