Coinbase design allows for mass, targeted phishing of its users
1–10 of 75 posts
Re: Coinbase design allows for mass, targeted phishing of its users
#2Re: Coinbase design allows for mass, targeted phishing of its users
#3Deja vu, man.
Re: Coinbase design allows for mass, targeted phishing of its users
#4firstinitiallastname@gmail.com is my "public" email address that is used for friends and what not.
genericemail@gmail.com is the email address I use for many retail sites.
I then have an email address dedicated to each commonly used site (Amazon, Coinbase, etc).
I also have Google two-factor authentication turned on for each email.
Re: Coinbase design allows for mass, targeted phishing of its users
#5Re: Coinbase design allows for mass, targeted phishing of its users
#6While I am glad he has made attempts to contact Coinbase, I felt like live execution of the attack was spammy, so my first instinct was the block the domain of the sender's email, which Coinbase passes through to me. In execution of his proof of concept, the author is likely badly ruining his spam score / sender score.
Re: Coinbase design allows for mass, targeted phishing of its users
#7Re: Coinbase design allows for mass, targeted phishing of its users
#8I didn't see any suggestion from the author, did I miss it?
More importantly, don't ever give the user the full name of someone whose email address they pulled out of thin air!
Re: Coinbase design allows for mass, targeted phishing of its users
#9This is obviously a serious issue. One way to mitigate it is to use email addresses that have specific purposes. firstinitiallastname@gmail.com is my "public" email address that is used for friends and what not. genericemail@gmail.com is the email address I use for many retail sites. I then have an email address dedicated to each commonly used site (Amazon, Coinbase, etc). I also have Google two-factor authentication…
Re: Coinbase design allows for mass, targeted phishing of its users
#10I didn't see any suggestion from the author, did I miss it?
Don't allow users to determine whether an email address is registered in your system. (Even if they click "forgot password" or "send money request"). More importantly, don't ever give the user the full name of someone whose email address they pulled out of thin air!