Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

61–70 of 294 posts

Re: Coinbase user emails and full names leaked

#61
post #45

This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails. Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same emai…

While that could be true, this list also includes the names; which would not be possible from what you're describing.

Re: Coinbase user emails and full names leaked

#62
post #40

Earlier quoted context omitted.

Coinbase isn't some random website made in a basement. It's a well funded, YC backed, known-founder company that complies with relevant banking law. There's absolutely nothing to suggest that they hold a partial reserve or have any ill intention whatsoever.

There's one reason to believe they have ill intention: their habit of ignoring serious user problems (lost deposits, security problems) until they're widely public. Their actions make clear that they are enormously untrustworthy.

That doesn't really suggest malice so much as ill attention. From their posts it sounds like they are stretched a little thin under the load, if they wanted to steal they would just be gone not occasionally unresponsive.

Re: Coinbase user emails and full names leaked

#63
post #19
post #16

Earlier quoted context omitted.

FWIW, https://plus.google.com/people/find You can find people's G+ profile if you guess the email correctly. I wouldn't be surprised if LinkedIn,Facebook,etc. had the same type of thing. I do think that coinbase-API should be rate-limited or unreplayable, but I'm _much more_ interested in where the email-list input data came from. My email wasn't in this alleged partial list, but if it was I'd like to know where they…

You can just type emails into the gmail account creation form to get results back on if the username was taken. This whole debacle is making a mountain out of a molehill.

SMTP's the API for checking if an address exists at any mail provider. Start sending a mail, if the server doesn't tell you there's no such mailbox right then, you can abandon the connection without sending a message through. No CAPTCHAs there either.

Re: Coinbase user emails and full names leaked

#64
Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list.

I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday (https://hackerone.com/reports/5200). I would be willing to bet that this brief list is actually all he got back, and he is just lying when he says "Full list much bigger."

Since the vulnerability was reliant on knowing the email first, and since my email used on Coinbase is not a known email that I publicize I doubt he would have been able to discover my Coinbase account, nor the Coinbase accounts of anyone else who uses a sufficiently random and unknown email address when signing up.

Re: Coinbase user emails and full names leaked

#65
post #40

Earlier quoted context omitted.

> Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Were you born yesterday? The steal-all-your-money rate of bitcoin businesses is running right around 100%, and you're going to lecture people that "they can only ever lose a small portion of all stored user funds"? Really?

Coinbase isn't some random website made in a basement. It's a well funded, YC backed, known-founder company that complies with relevant banking law. There's absolutely nothing to suggest that they hold a partial reserve or have any ill intention whatsoever.

You're right, there isn't anything suggesting that they hold a partial reserve.

And there won't be even when they do.

And when they close due to massive theft / loss of coin, and take all of their users' funds with them, that will be the first suggestion that any user hears of.

It happened to me. It's not fearmongering, it's fact.

Re: Coinbase user emails and full names leaked

#66
post #44

And this is why in addition to per site passwords, I also use per site email addresses. I like to be able to track who spams me and in case of leaks I like the ability to disable an email address...

how do you keep track of all the emails? and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

I have a catch-all setup at my domain that forwards to my main account. I can then setup a filter to disable an address if it starts getting spammed or is compromised.

Re: Coinbase user emails and full names leaked

#67
post #36
post #17

Earlier quoted context omitted.

Would you care explaining why it is that you believe email enumeration to be "insecure"? The data obtained is an email address and a name (only if the user filled in the "name" field). This may as well be treated as public information.

It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…

2 things:

First, the vast majority of attackers are more "smash and grab" than "stealthy jewel theft." They really don't care about leaving tracks, they are going for volume. Want to phish people for coinbase creds? Email a mass of people. Have a list of usernames/password from a data breach? Attackers have automated tools that will automatically try them against thousands of websites. It's more expensive and time consuming for them to try and leverage minor info disclosures to narrow down their attack than to simply brute the crap out of everything. The economies of scale devalue the info discloure.

Second, you are making an apples-to-oranges comparison. The boolean "Is/Is not a Coinbase user" provides a single data point, and is far less valuable than a hundreds if not thousands of datapoints about who is communicating with whom, and for how long. The single piece of meta-datUM of Coinbase pales in comparison to the meta-datA of phone logs.

Re: Coinbase user emails and full names leaked

#69
post #40

Earlier quoted context omitted.

Coinbase isn't some random website made in a basement. It's a well funded, YC backed, known-founder company that complies with relevant banking law. There's absolutely nothing to suggest that they hold a partial reserve or have any ill intention whatsoever.

You're right, there isn't anything suggesting that they hold a partial reserve. And there won't be even when they do. And when they close due to massive theft / loss of coin, and take all of their users' funds with them, that will be the first suggestion that any user hears of. It happened to me. It's not fearmongering, it's fact.

So ask them to prove their reserves if it bothers you so. Other large services have in the past.

Re: Coinbase user emails and full names leaked

#70
post #15

I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…

[deleted]

[deleted]
Post reply on HN