Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

41–50 of 294 posts

Re: Coinbase user emails and full names leaked

#42

Earlier quoted context omitted.

Wouldn't any evidence supporting the existence of the gag order be a violation of the gag order?

Yes. I read something about a library that had a sign up, "No government agents have been here." They would take down the sign during an investigation. Any one who knew the sign -was- there knew an investigation was underway. No gag order was broken. There is a name for this type of flag, but don't know it off hand.

Warrant Canary

http://en.wikipedia.org/wiki/Warrant_canary

Re: Coinbase user emails and full names leaked

#43
post #32

Earlier quoted context omitted.

Hot/cold storage as coinbase is using is probably better than any encryption. Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Manual processing of this means there is some sanity checking on large withdrawals too. Encryption affords you none of that, I would be happier with coinbase than storing on any other online wallet for this very reason.

Just invest in a raspberry pi as an offline cold storage bitcoin machine. They're not expensive, and armory (or electrum) work fine on it. Make a paper backup and keep it in a safety deposit box if you have a large amount of bitcoins.

That's not convenient. Coinbase is convenient. You're suggesting a ride on lawnmower as a substitute to a car. As a spending wallet Coinbase is fairly close to ideal.

Please read my post carefully next time.

Re: Coinbase user emails and full names leaked

#45
This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails.

Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same email address.

Re: Coinbase user emails and full names leaked

#47

I am curious why their contact form isn't posting over SSL http://support.coinbase.com/customer/portal/emails/new While I want to contact support for help, I am hesitant to fully disclose my issue in their contact form.

Here you go: https://coinbase.desk.com/customer/portal/emails/new

support.coinbase.com is just an alias for their Desk account.

Re: Coinbase user emails and full names leaked

#48
post #44

And this is why in addition to per site passwords, I also use per site email addresses. I like to be able to track who spams me and in case of leaks I like the ability to disable an email address...

how do you keep track of all the emails?

and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

Re: Coinbase user emails and full names leaked

#49
post #39
post #7

Earlier quoted context omitted.

Hi, nothing wrong with anonymity.

There's lots wrong with anonymity. But those wrongs are the price we pay for the benefits of anonymity. Thinking there's "nothing wrong with anonymity" is the kind of intellectual fallacy that makes it so hard to take 'net libertarians seriously.

Eh... I would say anonymity is problematic - not that there's something "wrong" with it though.

Re: Coinbase user emails and full names leaked

#50
post #44

And this is why in addition to per site passwords, I also use per site email addresses. I like to be able to track who spams me and in case of leaks I like the ability to disable an email address...

how do you keep track of all the emails? and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

If you’re using Gmail you can use address aliases, like me+site@domain.com. Unfortunately some websites will not validate that type of email address.
Post reply on HN