Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

131–140 of 294 posts

Re: Coinbase user emails and full names leaked

#131
post #72

I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…

You can only get so much for FREE, that's not Coinkite.com's model. We charge, but we answer email and fix issues.

But a quick read over your ToS defines bitcoins as having no value and not subject to law ("Bitcoins and Litecoins ("Coins") do not constitute a currency, an asset or a form of property at law or otherwise") and that you're not responsible if they mysteriously vanish ("Any purchase or sale of Coins, for money, virtual currency or other consideration, involves inherent risks and may lead to the complete loss of any value, virtual currency or other consideration, and you agree to wholly accept any and all such risk.")

Re: Coinbase user emails and full names leaked

#133

> Coinbase provides your full transaction history to the FBI, FinCEN and IRS every day. They are under a gag order. That is interesting accusation. Even if this is true, we will unlikely have evidence. Is there a serious risk to Coinbase users granted Gov is having full access?

This is highly likely to be true, and even if it's not, everyone should operate as if it's true. With the meteoric rise in price appreciation, I can't imagine the IRS at some point not requiring that the largest companies directly report users' income or capital gains to them. So don't be tempted to under-report your bitcoin gains. Similarly, the FBI and other money regulators have clearly shown their strong interest…

What form would the IRS require it to be filed as? I don't know of any industry/company that is required to file a monthly/daily 1099 for customers. Even the banks are only required to file that stuff yearly via a Schedule D.

Re: Coinbase user emails and full names leaked

#134

Earlier quoted context omitted.

Same. It seems like it can't happen until it happens, and then you face the reality that it happened. It sucks, and there's absolutely no protection for consumers from it. There's not even any insurance policy that exchanges can purchase yet, which is pretty much the only hope at this point.

Wouldn't that add a transactional cost to bitcoin, not unlike PayPal or Visa?

I've spent a couple months trying to come up with ways to protect bitcoin consumers, and the only thing I can think of is for exchanges to purchase some kind of high-risk insurance which will cover losses by the exchange. Nothing else will protect users, as far as I can tell, precisely because of bitcoin's irreversible transactions.

Honestly, the best thing for the bitcoin ecosystem is to learn from Paypal and Visa, and to emulate their good qualities. I know it's popular to hate on the existing ways of doing things, but the existing ways have a lot of hidden wisdom embedded in them.

Re: Coinbase user emails and full names leaked

#135
post #105

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.

[deleted]

Re: Coinbase user emails and full names leaked

#136

Earlier quoted context omitted.

That does nothing to increase the security of your accounts, since effectively the email address is the same.

It keeps phishing attacks from being able to cross services (since if you get a citibank email to your coinbase email that would be a big flag) and it reduces the attack surface on other sites. I use email.site@domain.com for this purpose and it makes it handy to see who has somehow lost/disclosed my email to third parties and not informed me (FreshDirect for example)

email.site@domain.com is at least a distinct email address, unlike using +. Especially if you use different passwords for each account, it means if one of the emails is compromised then the attacker can't use it to recover passwords of your other sites.

Re: Coinbase user emails and full names leaked

#137

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

Fred from Coinbase here.

There is no full list, and there is no leak. We're drafting a more formal response now.

Re: Coinbase user emails and full names leaked

#138
post #61
post #45

This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails. Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same emai…

While that could be true, this list also includes the names; which would not be possible from what you're describing.

If you put in an active email, it sends back the name through the API. Similar to the way that snapchat API bug sent back a username with a phone number as input.

Re: Coinbase user emails and full names leaked

#139
post #45

This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails. Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same emai…

Actually, many password forget forms do not provide any information about whether the email was recognized or not. More than once I've seen a message along the lines if "If the email entered was associated with an account, a password reset has been sent.".

EDIT: On the other hand even if the response is always the same, I expect most implementations to be vulnerable to a timing attack ;)

Re: Coinbase user emails and full names leaked

#140

Earlier quoted context omitted.

If you use gmail, you can use youremail+anything@gmail.com, and it will all get forwarded to youremail@gmail.com. This is incredibly handy for noticing who is sending you spam. I'll also use it for sites that I know are going to send me spam, and then immediately create a filter than deletes emails sent to joe+annoyingsite@gmail.com (note: that's not my real email)

Does this actually prevent true spammers, or only emails you consider spam, but the sender thinks is worthwhile? Otherwise, as a 'true' spammer, why wouldn't you just always strip off everything after the plus when adding the email to your distribution list?

I use _, not "+" and anybody else might use "." or "-" depending on the configuration of their mail server. Sure, you can always add the full email and every possible stripped email to your lists, but in practice, few people seem to do that (judging by the amount of spam I get to me_randomstuff@example.net as compared to me@example.net).
Post reply on HN