Live data from Hacker News

Coinbase design allows for mass, targeted phishing of its users

blog.shubh.am

1–10 of 75 posts

Re: Coinbase design allows for mass, targeted phishing of its users

#4
This is obviously a serious issue. One way to mitigate it is to use email addresses that have specific purposes.

firstinitiallastname@gmail.com is my "public" email address that is used for friends and what not.

genericemail@gmail.com is the email address I use for many retail sites.

I then have an email address dedicated to each commonly used site (Amazon, Coinbase, etc).

I also have Google two-factor authentication turned on for each email.

Re: Coinbase design allows for mass, targeted phishing of its users

#6
I received a phishing email from the author. I guess he must have scraped my email address from a blog post I wrote about bitcoin and coinbase.

While I am glad he has made attempts to contact Coinbase, I felt like live execution of the attack was spammy, so my first instinct was the block the domain of the sender's email, which Coinbase passes through to me. In execution of his proof of concept, the author is likely badly ruining his spam score / sender score.

Re: Coinbase design allows for mass, targeted phishing of its users

#8
post #7

I didn't see any suggestion from the author, did I miss it?

Don't allow users to determine whether an email address is registered in your system. (Even if they click "forgot password" or "send money request").

More importantly, don't ever give the user the full name of someone whose email address they pulled out of thin air!

Re: Coinbase design allows for mass, targeted phishing of its users

#9
post #4

This is obviously a serious issue. One way to mitigate it is to use email addresses that have specific purposes. firstinitiallastname@gmail.com is my "public" email address that is used for friends and what not. genericemail@gmail.com is the email address I use for many retail sites. I then have an email address dedicated to each commonly used site (Amazon, Coinbase, etc). I also have Google two-factor authentication…

[deleted]

Re: Coinbase design allows for mass, targeted phishing of its users

#10
post #8
post #7

I didn't see any suggestion from the author, did I miss it?

Don't allow users to determine whether an email address is registered in your system. (Even if they click "forgot password" or "send money request"). More importantly, don't ever give the user the full name of someone whose email address they pulled out of thin air!

Seems viable, and if you had previous "relationship"/transaction with this user you can display name etc.
Post reply on HN