[HN Gopher] PayPal data breach notification
       ___________________________________________________________________
        
       PayPal data breach notification
        
       Author : pmoriarty
       Score  : 187 points
       Date   : 2023-01-26 10:40 UTC (12 hours ago)
        
 (HTM) web link (apps.web.maine.gov)
 (TXT) w3m dump (apps.web.maine.gov)
        
       | alpos wrote:
       | "We have also secured the services of Equifax to provide identity
       | monitoring services at no cost to you for two years. Below please
       | find information on signing up for a complimentary membership to
       | Equifax's identity monitoring services, including key product
       | features"
       | 
       | Really PayPal? You mean this Equifax?
       | 
       | https://en.wikipedia.org/wiki/2017_Equifax_data_breach
       | 
       | The security breach problem altogether has been turned in to a
       | source of extra profit for the credit reporting companies whose
       | faulty systems, lack of data verification, and resulting poor
       | data quality are the root cause of these issues in the first
       | place.
       | 
       | The problem has never been "oh no someone stole your identity!".
       | Identity can not be stolen, only temporarily misattributed in the
       | eyes of one party or another.
       | 
       | The actual problem is that companies like banks and credit card
       | issuers don't actually know who they are dealing with and don't
       | want to put any effort in to verifying that. Using just a few
       | pieces of already available, static information about a customer
       | was never enough to say you actually know who your company is
       | signing a contract with.
       | 
       | Calling it "identity theft" when someone feeds your faulty signup
       | process incorrect information is merely a means of passing the
       | problem with your systems off to the customer. Now we're going as
       | far as pretending the root cause of this stupidity can also sell
       | us the cure? Nonsense.
       | 
       | If anyone ever "steals my identity", I'm going to sue the credit
       | reporters for libel. They have admitted before that some 70% of
       | their records contain inaccurate information and they know full
       | well that a few bits of static information is not enough the
       | identify an individual among hundreds of millions. They also know
       | they don't do anything to establish that any new reports coming
       | in from partner businesses are actually real and accurate. Yet
       | they still peddle that inaccurate information to third parties.
       | That is the same as if a journalist made up a story saying you
       | did some shit you didn't do. They are knowingly giving out
       | information about a person that is either provably false or which
       | they have no good reason to believe is true in a way that can
       | cause financial harm and loss of reputation. Classic libel.
       | 
       | Further, if some business reported that I took a loan from them
       | when I didn't, that isn't my problem, it's theirs. They failed to
       | adequately verify who they were dealing with. Not my problem.
       | Reporting that inaccuracy to a third party who then broadcasts
       | that to a bunch of other companies, is also libel.
       | 
       | They can make a case that they didn't know for sure that their
       | claim that I owe them was false at the time, but they actually
       | never had a good reason to believe it was true. Static
       | information alone, especially that which we already know is in
       | circulation among public entities, is not a valid way of
       | identifying who you are dealing with. Pretending that it is
       | anyway is just bad business.
       | 
       | People need to hold these businesses accountable for the damage
       | their faulty system designs are causing.
        
       | scrps wrote:
       | Wondering if this isn't related to the LastPass breach?
       | 
       | Paypal's 2FA is a bit of a joke. IIRC (this was quite some time
       | ago) when I went to initially setup 2FA SMS was the only option,
       | eventually they added support for authenticators but you can just
       | click get a text instead of the authenticator. Last time I
       | checked there was no way to tell paypal to only accept OTPs from
       | an authenticator.
        
         | troymc wrote:
         | Probably not. "Credential stuffing" means getting a big list of
         | formerly-leaked usernames and passwords and trying them
         | _everywhere_. It mainly targets people who use low-entropy
         | passwords or who reuse the same password on multiple sites.
        
       | looseyesterday wrote:
       | What are the chances this is bigger than they claim?
        
       | app4soft wrote:
       | Meanwhile _Twitter_ hides my tweets about _PayPal.Me_ still
       | working in Russia.[0]
       | 
       | [0] https://news.ycombinator.com/item?id=34531489#34531574
        
       | TrickardRixx wrote:
       | PayPal previously refused to acknowledge a 2FA bypass
       | vulnerability submitted to their HackerOne program.
       | 
       | https://cybernews.com/security/we-found-6-critical-paypal-vu...
        
       | seagull-action wrote:
       | I personally wouldn't call it a data breach as such if it's just
       | credential stuffing, but it's great that Paypal put out a notice
       | on it so their customers are aware.
        
       | dgudkov wrote:
       | Tried to configure 2FA on PayPal. Adding only 1 authenticator app
       | is allowed (why not more?). Failed to recognize Yubikey in
       | Firefox.
       | 
       | It's a leading payment processor. They have lots of money and
       | developers. The state of things is pity.
        
         | Terretta wrote:
         | Who engineered this thing? It's not like it's rocket science.
         | 
         | Oh wait...
        
       | gggggg5 wrote:
       | Requiring businesses to file breach notifications over credential
       | stuffing attacks seems completely insane to me. What's next?
       | Breach notifications over phishing campaigns?
       | 
       | Perhaps the goal is to render breach notifications useless by
       | flooding them with nonsense like this?
        
         | RhodesianHunter wrote:
         | What's insane is thinking that a bank that handles people's
         | money shouldn't be required to report a coordinated successful
         | attack, regardless of whether their technology is at fault.
        
           | prophesi wrote:
           | If all it takes is someone to download one of the countless
           | publicly-available-on-github plaintext password compilations
           | and automate login attempts to require a company to file a
           | breach notification, I think all of the top services in the
           | world would have to file one every hour.
        
           | gggggg5 wrote:
           | There are thousands of coordinated successful phishing
           | campaigns going on against Paypal every day, what value would
           | that reporting provide to anyone?
        
       | Beestie wrote:
       | Awesome. They are providing 24 mo identity theft protection by
       | Equifax. So the day after the fox broke into the henhouse, they
       | are going to secure the premises by adding a sign: "Please do not
       | eat the chickens"
       | 
       | Gotta hand it to Equifax, they know how to sell nothing for
       | something.
        
       | yalogin wrote:
       | Why do companies offer only 2yrs of identity protection coverage
       | for breaches? There are tons of these happening and so people can
       | wait a couple of years to use them if it's going to be less of a
       | hassle. Ofcourse, I don't trust that the identity protection
       | coverage is of any use, but still trying to think about the
       | effectiveness of the data after 2 years. Is there a reason to
       | believe the information is not useful after 2 yrs? Why the 2yrs?
       | It should be at least 10yrs if not more to be meaningful.
        
         | autoexec wrote:
         | > Why do companies offer only 2yrs of identity protection
         | coverage for breaches?
         | 
         | Two years seems like the minimum they feel they can get away
         | with. They just need to make it seem like they've done
         | "something" to compensate their victims out of fear that if
         | they didn't some regulation will come along that requires that
         | they actually make up for the harm their negligence has caused
         | in an actually meaningful (and more costly) way.
        
       | progbits wrote:
       | Two weeks to detect (not great), another month to disclose
       | (worse).
       | 
       | "Only" 35k affected so must be some narrow scope. The linked page
       | doesn't seem to provide more details.
        
         | Zetobal wrote:
         | There was nothing to detect and there was nothing to disclose
         | it was a stuffing attack. The fallout of another company's
         | breach, they took the proactive course of action to mitigate
         | and inform their customers it should be applauded and not
         | condemned.
        
           | progbits wrote:
           | Apparently I can't read today, sorry for the stupid comment.
           | Can't edit it anymore.
        
       | snorremd wrote:
       | If I read this correctly this is a case of credential stuffing
       | meaning the breach isn't really related to PayPal as much as
       | people had credentials stolen other places and had used the same
       | ones at PayPal. Maybe PayPal needs to enforce 2FA if they don't
       | already do. 2FA SMS factor should be discontinued for any
       | financial or otherwise important/sensitive service as SIM jacking
       | is apparently quite easy.
       | 
       | But anyone with properly secured accounts seems to not have been
       | affected by this breach.
        
         | latchkey wrote:
         | https://www.paypal.com/us/cshelp/article/what-is-2-step-veri...
        
         | brador wrote:
         | I don't like the term credential stuffing. It is inaccurate by
         | definition. Stuffing - "a material or substance used to stuff
         | something".
         | 
         | What alternative names could we use?
         | 
         | Credential attack?
         | 
         | Credential reuse attack?
         | 
         | Secondary credential attack?
        
           | doubled112 wrote:
           | It's a verb.
           | 
           | to stuff - to push something into a small space, often
           | quickly or in a careless way
           | 
           | https://dictionary.cambridge.org/dictionary/english/stuff
           | 
           | As in "I am going to try these credentials quickly and
           | carelessly and see if they get me in."
        
           | abathur wrote:
           | Credential spray-n-pray
        
             | chatmasta wrote:
             | Credential stuffing and password spraying are two distinct
             | classes of attack. [0] Stuffing is when you try passwords
             | for certain users (hoping they re-used a known password),
             | and spraying is when you try common passwords for every
             | username.
             | 
             | [0]
             | https://security.stackexchange.com/questions/209266/what-
             | are...
        
         | kennydude wrote:
         | PayPal, at least for me, forces FaceID and an SMS 2FA to access
         | it at all which is crazy. Probably would be great if they moved
         | away from SMS though :(
        
           | perch56 wrote:
           | You can enable or disable FaceI ID from the settings. Just
           | curious, why is using Face ID crazy?
        
         | digitallyfree wrote:
         | I don't use PayPal but was told by a user that their 2FA SMS
         | system isn't really a second factor, but rather it replaces the
         | password. Basically when you log in (with username only) it
         | sends you an SMS code and you enter the code to log in with no
         | password necessary. So basically this becomes a single factor.
         | 
         | I hope they got rid of this feature now and went back to
         | "traditional" 2FA requiring both a password and code.
        
         | toastal wrote:
         | I've had to ignore my account. I originally want TOTP 2FA, but
         | it wasn't an option. I set up 2FA through Google Voice because
         | my number changes frequently. A few years later I tried to log
         | in and Google Voice has been blocked as a 2FA option for SMS. I
         | go to seek support and you, circularly, need to be
         | authenticated to get support for authentication, and asking
         | support on Twitter got me banned from their account.
         | 
         | The last 2 years directly emailed all independent sellers to
         | set up alternative payment options to not go through such a
         | careless operation.
        
           | eloff wrote:
           | Always have a backup payment processor. PayPal especially,
           | but even Stripe will shut you down or freeze your balance
           | with little recourse.
           | 
           | Amazon killed my parents business by just sheer incompetence
           | and support took a year to get partially back to operation,
           | by which time it was over.
           | 
           | Facebook incorrectly nuked my wife's Instagram account and
           | hopes of becoming an influencer. No recourse.
           | 
           | Google can ban your account with your email with no recourse.
           | You lose your email history, contacts, documents, etc with no
           | way to login to a myriad of online services.
           | 
           | I'm really low on patience with the big tech companies. I
           | hope the government reins them in.
        
             | bipson wrote:
             | As much as I have sympathy for the pain (besides the
             | influencer thing) - what exactly do you expect from the
             | government here?
             | 
             | And I say this as European, I mean, we at least have _some_
             | regulations...
        
               | f-securus wrote:
               | I think support shouldn't be 100% automated. The big tech
               | companies are automating everything and sometimes those
               | false positives need to be corrected and there isn't a
               | way to actually do so. I don't know how the government
               | could enforce proper support but I believe something as
               | simple as requiring the ability to discuss your critical
               | issue with a human being as a start.
               | 
               | Then you get into what is a 'critical' issue but I think
               | being locked out of your account that is used as a
               | gateway to multiple other accounts qualifies.
        
               | ensignavenger wrote:
               | At the very least the right to get a dump of your data
               | after they close your account.
               | 
               | Also, for money things like PayPal, they should only be
               | able to hold your funds for a reasonable amount of time,
               | then they have to transfer them to your bank account.
               | They should not be allowed to just keep your money.
               | 
               | For sales of digital items, they should not be allowed to
               | revoke your access to the items you have bought. Maybe
               | they should just have to provide a basic file download
               | for a certain amount of time.
        
               | RhodesianHunter wrote:
               | Believe it or not here in the US we have a lot of
               | regulations as well. They're just designed to favor the
               | big guy.
        
               | bipson wrote:
               | That's not what the rest of the world considers a
               | "regulation"
        
               | eloff wrote:
               | I believe those are called barriers to entry to protect
               | vested interests. Also known as pulling the ladder up
               | behind you. Why that works in the US is beyond me. I
               | recall a recent study from one of the Ivy leagues that
               | shows that historically the elected representatives favor
               | the elite over the people in the US.
               | 
               | I think the elected representatives have to represent the
               | people, otherwise you don't really have a democracy,
               | right?
        
               | michaelteter wrote:
               | Regulations that could be imposed:
               | 
               | 1. When a service is blocked or terminated, the
               | terminating company must provide clear and specific
               | reasons for the termination (they almost never do this
               | now)
               | 
               | 2. Additionally, there must be a human support channel to
               | discuss the matter - even if it requires payment for the
               | privilege of gaining support help (think 900 numbers of
               | the past)
               | 
               | 3. Human support and decision paths must be documented
               | and followed such that a final decision can be understood
               | within the context of the rules of the organization
               | (thereby enabling possible efficient legal options for
               | the consumer to further dispute the ruling)
               | 
               | 4. As other people have noted, having access to export
               | your data if you are being permanently blocked from the
               | service
               | 
               | 5. Having financial compensation (refunds) or post-
               | service DRM access to content you have paid for
        
               | Brian_K_White wrote:
               | There's lot's of things government could do. Start with
               | codifying some concepts that define when a service is
               | responsible for having too much impact on a user's life,
               | and attach responsibility to that, instead of just
               | 'private company, do anything you want'
               | 
               | It's not an accurate or sufficient or desirable
               | representation of reality to allow these various big
               | companies to actively seek out having you entrust them
               | with parts of various critical paths in your life, and
               | then be able to nuke those with no protection or recourse
               | on your part.
               | 
               | In 1975 when no one had an email address or a cell phone,
               | and neither were required to do anything in life, it was
               | fine to treat them like luxiries that if you lose them,
               | so what?
               | 
               | That was still true but just a bit less so a few years
               | later, and it's just been gradually becoming less so
               | every year, and by now, it is simply not true at all.
               | 
               | It should essentially be illegal for a service provider
               | to completely break some of these services without some
               | sort of graceful shutdown or hand-off process, in the
               | same way and for the same reasons it's illegal to shut
               | off electricity and gas and phone in a lot of cases even
               | after the subscriber has failed to pay. They get shut off
               | eventually of course, but there are exceptions and ways
               | for the subscriber to fight, and they are mandated by the
               | government, not out of the goodness of the power
               | companies hearts. Basically the power company isn't
               | allowed to just let grandma freeze in the winter even if
               | she fails to pay. It's not unfair to the power company.
               | The investors in the power company are free to be in some
               | other business if they don't like those terms.
               | 
               | Today, an email account should not be treated the same
               | way as a spotify account, even if you're not even
               | charging money for the service. If you don't like that,
               | you don't have to offer an email service at all.
               | 
               | The requirement I imagine is some minimal level of
               | continued function enough to complete other account
               | management procedures, which means being able to both
               | receive and send at least some emails. Maybe a limited
               | amount, maybe limited attachment size etc, but enough to
               | at least send the one or few emails from the previously
               | recognized address to other parties as part of the proof
               | of identity to direct them to a new address.
               | 
               | This even in cases where the account was terminated for
               | supposed cause like illegal activity.
               | 
               | This means that one of the other things government can do
               | is recognize that exception for liability. The government
               | can determine not to penalize a service provider or allow
               | others to sue them for having one of these accounts
               | active at that limited level of functionality if the
               | account sends someone a phising email or something.
               | 
               | Or maybe the procedure is the accounts do stop
               | functioning so no email is passed, but, it can still be
               | used by the owner to contact the service provider to
               | invoke some kind of recourse procedure 9f they need it.
               | So the spammer is blocked but mom can still jump through
               | hoops and eventually regain access, including old mails
               | and maybe even including unread received mails while it
               | was down.
               | 
               | There are all kinds of things a government can do, and
               | fully fairly and defensibly and officially, just by
               | codifying some principles.
               | 
               | What do I expect from the government? Something. They can
               | absolutely do something. It's work to work out exactly
               | what and how and develop some consistent rational legal
               | theory to base it on, but that it literally their job is
               | to to exactly that.
        
               | BolexNOLA wrote:
               | >As much as I have sympathy for the pain (besides the
               | influencer thing)
               | 
               | Why not? You have no clue what she was doing and it's a
               | totally viable source of income for plenty of people.
        
               | f-securus wrote:
               | Because influencer is another way to say individual
               | advertiser. Nobody wants more advertising.
        
               | eloff wrote:
               | If that were true, influences wouldn't exist. Clearly
               | they can make money because they add value for people.
               | 
               | If that value is actually improving people's lives it's
               | another matter, but from an economics standpoint it seems
               | to exist.
        
               | f-securus wrote:
               | Advertising works because it is a psychological hack.
               | Influencers are using the same hack and once it becomes
               | more than a passion or hobby project then the monetary
               | incentive perverts their judgement.
               | 
               | I'm all for people sharing their knowledge and hobbies to
               | inform others but the term 'influencer' has a connotation
               | in which they are earning money from 'influencing' others
               | and that seems an awful lot like basic advertising to me.
        
               | BolexNOLA wrote:
               | >I'm all for people sharing their knowledge and hobbies
               | to inform others
               | 
               | And I'm all for them getting paid to do so. I'm not sure
               | where you draw the line. Is a cocktail influencer sharing
               | a cool hobby or pushing a product? The answer is usually
               | "both." So where do they fit in for you?
        
               | f-securus wrote:
               | If the cocktail influencer started making videos with the
               | intent of getting paid then their judgement is already
               | clouded. Even if they decided they wanted to do the
               | morally correct thing and give honest reviews, their
               | livelihood now depends on this income and as such they
               | are biased subconsciously. Ultimately they are self-
               | employed advertisers. We need less advertising in this
               | world, IMO.
        
               | BolexNOLA wrote:
               | So making movies with the intention of getting paid means
               | my judgment is clouded? Can't a job be a job? Does it
               | have to always be in the service of some grander or more
               | artistic purpose?
        
               | autoexec wrote:
               | You aren't wrong. "Influencer" is another word for
               | "manipulator" and the world sure doesn't need more ads,
               | but companies wanting to take from us love influencers
               | because a lot of people, children especially, consume
               | that "content" without even recognizing that they're
               | watching an ad.
        
               | eloff wrote:
               | I think you missed my point. The fact that these people
               | have the audience that they have is because people want
               | to see their content.
               | 
               | Whether or not they monetize that via advertising or not
               | it's largely irrelevant to that value proposition.
        
               | BolexNOLA wrote:
               | > Nobody wants more advertising.
               | 
               | Seems plenty do given the number of influencers who have
               | made it into basically a career. I in some way share your
               | cynicism towards it, but there are plenty of jobs we
               | don't "need" yet don't look down on in the same way. For
               | all you know this guy's wife is spreading valuable
               | information and genuinely helping people. Not all
               | influencers are Andrew Tate and such. Hell my wife's
               | cousin is big into legos and has a thriving instagram
               | showing off their builds and talking about what goes in
               | to them. Tons of hobbyists genuinely enjoy their insight.
               | I don't see the harm.
        
               | wasmitnetzen wrote:
               | In Germany, there has been a high-level court decision
               | last year about requiring a "proper" recourse process[1].
               | 
               | [1]: https://www.sueddeutsche.de/politik/facebook-bgh-
               | urteil-1.53... (German)
        
               | [deleted]
        
               | eloff wrote:
               | If a company has your livelihood, bank balance, etc by
               | the balls - they should at least be required to offer a
               | minimum level of human support with a path for escalating
               | things or a way to reasonably handle disputes with a
               | neutral adjudicator. The stakes are too high to simply
               | leave decisions up to algorithms.
        
               | eminent101 wrote:
               | > If a company has your livelihood, bank balance, etc by
               | the balls
               | 
               | Whose fault is it that people are relying on free email
               | service (with no human support) for critical things like
               | livelihood, bank balance, etc.? Is the provider of a free
               | email service liable for the damages they can cause? What
               | do their terms and conditions say about it? Do they have
               | a disclaimer in there for this kind of things?
        
               | Retric wrote:
               | At a minimum long term freezing an account with a
               | positive balance should be treated as simple theft.
               | 
               | It's fine if they want to arbitrarily flag something as
               | fraud and refund money, but saying something is
               | suspicious therefore we keep your money isn't.
        
               | eloff wrote:
               | They should have to pay interest on seized funds. Like
               | fed rate +5%. Then it will only happen in serious cases
               | and they will resolve it quickly.
        
             | judge2020 wrote:
             | The problem is that few card processors will underwrite you
             | for your small transaction volume at the start, so
             | PayPal/Braintree and Stripe are go-to solutions with the
             | promise to scale up without ever needing to rewrite your
             | payment processing code. Once you get big, you can either
             | seek out a real contract with the services (but this
             | requires a lot of scale) or go for something like Adyen or
             | Chase which seem to still require some level of scale but
             | not a million dollars a day or anything.
        
           | vorpalhex wrote:
           | You should be able to have them close your account by sending
           | them a formal letter.
        
           | compsciphd wrote:
           | paypal works fine with my google voice account. get sms's and
           | copy/paste them into the field.
        
           | gorbachev wrote:
           | Same. Can not log into my Paypal account any more, because
           | they don't accept Google Voice numbers as valid phone numbers
           | any longer.
        
           | latchkey wrote:
           | I use TOTP on my Paypal account.
           | 
           | https://www.paypal.com/us/cshelp/article/what-is-2-step-
           | veri...
        
       | londons_explore wrote:
       | Most companies wouldn't even act on a credential stuffing attack
       | against their users. They'd shrug and say 'not our problem if our
       | users don't secure their passwords properly'.
       | 
       | Kudos to Paypal here for considering it a breach, and reporting
       | it as such.
        
         | insanitybit wrote:
         | Lots of companies deal with credential stuffing, especially a
         | large targeted attack.
        
         | [deleted]
        
         | fmajid wrote:
         | And I'd agree. Their lawyers probably made them do it.
        
           | londons_explore wrote:
           | As a bank, your agreements are with the actual humans, and
           | your duty is to protect their money.
           | 
           | The fact that you choose to use usernames and passwords to
           | authenticate humans is your choice. It is well known that
           | humans don't secure passwords well (reuse, writing on postit
           | notes, etc). As a bank, any losses attributable to someone
           | evil finding/guessing a password are your own.
           | 
           | That's why credential stuffing counts as a breach. Even
           | though most banks will try to tell you that it's your
           | responsibility to protect your passwords, the law doesn't see
           | it that way.
        
             | bob1029 wrote:
             | > As a bank
             | 
             | Technically, Paypal is not regulated as a bank (per FDIC).
             | That said, they certainly have immense fiduciary & privacy
             | duty to their customers considering the format of their
             | business.
        
               | moxli wrote:
               | > Technically, Paypal is not regulated as a bank
               | 
               | PayPal has a banking license in Luxembourg which allows
               | them to operate in Europe.
               | 
               | I guess it depends on the region/country.
        
             | boring_twenties wrote:
             | Well that sucks for those of us who can use passwords
             | effectively, instead we all get this SMS 2FA crap which is
             | both more annoying and less secure.
        
       | survirtual wrote:
       | [flagged]
        
         | phoe-krk wrote:
         | And people (especially here on HN) really can't see why so many
         | are invested in and believe in actual money?
         | 
         | Your shitcoins are being hoarded by incompetent people in
         | giant, minimally secured exchanges not to provide you with a
         | better service, but to make a very small number of people
         | bucket loads of money.
         | 
         | They put in minimal viable effort to provide a minimal viable
         | service and make money hand over fist without consequence when
         | their incompetence result in your cryptocurrencies that you
         | entrusted them with being rug-pulled.
         | 
         | Once that crypto is "compromised" it is free for the attacker
         | to use for any reason, outside the ToS defined by the
         | exchanges. They are not held accountable, there is a proven
         | record of no oversight nor any accountability.
         | 
         | Do you really wonder why people are putting their faith and
         | confidence in actually regulated currencies as opposed to these
         | joke shitcoins?
         | 
         | Look around you. The Web3 is going great[0]. Get out while you
         | still can.
         | 
         | [0] https://web3isgoinggreat.com/
        
           | rajamaka wrote:
           | The common retort to this is, "well you should be holding
           | your coins in your own physical wallet".
           | 
           | Usually from a person who stores their life saving of
           | dogecoin in some weird 25% APR Ponzi.
        
             | danuker wrote:
             | Ah, I remember the Ledger customer data leak. Just as
             | incompetent, even for a hardware wallet.
        
           | mypastself wrote:
           | Your argument entirely relies on the assumption that the OP
           | stores significant amounts of funds on an exchange.
        
             | lm28469 wrote:
             | The extreme vast majority of crypto owners are on exchanges
        
               | mypastself wrote:
               | It's a fair assumption the OP is not one of them given
               | the website we're on, and their stated opposition to
               | handing custody of their funds to others.
               | 
               | Also, plenty of retail "investors" seem to be moving away
               | from the exchanges:
               | 
               | https://www.reuters.com/technology/cryptoverse-bitcoin-
               | inves...
        
               | frankenst1 wrote:
               | Don't know about crypto, but for Bitcoin:
               | 
               | ~11% of the Bitcoin supply is held by exchanges, and it
               | decreases on average by 2,500 BTC per day or ~5% per year
               | (over the last 3 years).
        
               | ilyt wrote:
               | That just means they are not stored there as often, not
               | that the exchanges are where most bitcoin related
               | transactions happen
        
           | survirtual wrote:
           | Don't use an exchange?
           | 
           | This isn't as clever as you think it is, and it will not age
           | well. Fiat does not have a future within a spacefaring
           | civilization.
           | 
           | Cryptocurrency is not an exchange. Bitcoin is not an
           | exchange. The technology is unprecedented and revolutionary.
           | It removes parasitic intermediaries and allows the common man
           | to transact at light speed directly with each other.
           | 
           | The same old parasites are hard at work to inject themselves
           | in the process. How anyone could conflate centralized
           | exchanges with decentralized protocols is beyond me. May as
           | well complain at the sun for being hot or complain at water
           | for being wet.
           | 
           | Water is a good example actually. You know, it is possible to
           | drown with water, should we all stop drinking it? Some people
           | even take the water, bottle it up, then sell it back to us.
           | Those companies must be water, I don't like them. We should
           | stop using water because it's centralized with Nestle.
        
           | frankenst1 wrote:
           | Just use Bitcoin. Don't trust anyone except yourself. You can
           | store your coins in your phone, hardware wallet, paper
           | wallet. You can encode it in steel and bury it in your
           | backyard. You can "horcrux" them (e.g. via MultiSig or SSS)
           | and store the parts (and copies of them) at different
           | locations (friends, family, attorney, ...). Or put them in a
           | safe deposit box if you like. Put a small amount on your
           | phone and you can send them in seconds via the Lightning
           | Network to anyone in the world at minimal fees, without
           | relying on or needing permission from anybody else.
           | 
           | Few actual need custodial services and nobody needs the
           | greedy shitcoin casino. Decentralize. Be your own bank.
        
         | dmitriid wrote:
         | Wow. Haven't seen one of you in a wild for while now.
        
           | survirtual wrote:
           | Trust me, you've never seen one of me before.
        
         | wil421 wrote:
         | I've had a couple instances of fraud on my Bank account. Every
         | time it was refunded in full within 2-3 business days.
         | 
         | Beyond that all of my cash is insured by FDIC. If Bank of
         | America decided to pull an FTX and scam away my money I'm
         | getting it back.
        
           | rationalist wrote:
           | Bank of America's deposits were 1.4 trillion in Feb 2021.
           | FDIC's Deposit Insurance Fund was 125 billion in Dec 2022.
           | 
           | You aren't getting your money back if BoA loses it all.
           | 
           | https://newsroom.bankofamerica.com/content/newsroom/press-
           | re...
           | 
           | https://www.fdic.gov/analysis/quarterly-banking-
           | profile/fdic...
        
           | loloquwowndueo wrote:
           | Just remember FDIC insurance has limits; I know you know how
           | much you have and it might not be over the limit but folks
           | should know "all of my cash is insured" may not be entirely
           | accurate.
        
             | wil421 wrote:
             | Correct, the limit is $250k for anyone curious. It's $250k
             | per co-owner for joint accounts.[1]
             | 
             | [1]https://www.fdic.gov/deposit/diguidebankers/documents/jo
             | int-...
        
         | hnlmorg wrote:
         | Bitcoin ledgers are public so your data is still out there.
         | 
         | Plus crypto currencies are subject practically zero oversight
         | and accountability so the situation is even worse there. Hence
         | why you hear about so many exchanges going bang.
         | 
         | The problems cryptocurrencies attempt to solve are different
         | from the arguments you're favouring them for.
        
           | deweller wrote:
           | Cryptocurrency exchanges are not the same thing as
           | cryptocurrencies. And not all exchanges are created equal.
           | 
           | Yes it is the wild west out there and consumers have gotten
           | hurt. It is unfortunate. But crypto does serve a real and
           | needed function of decentralized digital cash. I'm optimistic
           | we'll have good regulated exchanges someday.
        
       | mrguyorama wrote:
       | As a resident of the state in question, I'm curious as to why
       | this comes from our state. Did paypal not have to report this
       | anywhere else?
        
       ___________________________________________________________________
       (page generated 2023-01-26 23:02 UTC)