I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…
You can only get so much for FREE, that's not Coinkite.com's model. We charge, but we answer email and fix issues.
Coinbase user emails and full names leaked
131–140 of 294 posts
Re: Coinbase user emails and full names leaked
#132How is that legal/constitutional? It's one thing to monitor one "target's" transactions, but everyone's?
Re: Coinbase user emails and full names leaked
#133> Coinbase provides your full transaction history to the FBI, FinCEN and IRS every day. They are under a gag order. That is interesting accusation. Even if this is true, we will unlikely have evidence. Is there a serious risk to Coinbase users granted Gov is having full access?
This is highly likely to be true, and even if it's not, everyone should operate as if it's true. With the meteoric rise in price appreciation, I can't imagine the IRS at some point not requiring that the largest companies directly report users' income or capital gains to them. So don't be tempted to under-report your bitcoin gains. Similarly, the FBI and other money regulators have clearly shown their strong interest…
Re: Coinbase user emails and full names leaked
#134Earlier quoted context omitted.
Same. It seems like it can't happen until it happens, and then you face the reality that it happened. It sucks, and there's absolutely no protection for consumers from it. There's not even any insurance policy that exchanges can purchase yet, which is pretty much the only hope at this point.
Wouldn't that add a transactional cost to bitcoin, not unlike PayPal or Visa?
Honestly, the best thing for the bitcoin ecosystem is to learn from Paypal and Visa, and to emulate their good qualities. I know it's popular to hate on the existing ways of doing things, but the existing ways have a lot of hidden wisdom embedded in them.
Re: Coinbase user emails and full names leaked
#135Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…
There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.
Re: Coinbase user emails and full names leaked
#136Earlier quoted context omitted.
That does nothing to increase the security of your accounts, since effectively the email address is the same.
It keeps phishing attacks from being able to cross services (since if you get a citibank email to your coinbase email that would be a big flag) and it reduces the attack surface on other sites. I use email.site@domain.com for this purpose and it makes it handy to see who has somehow lost/disclosed my email to third parties and not informed me (FreshDirect for example)
Re: Coinbase user emails and full names leaked
#137Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…
There is no full list, and there is no leak. We're drafting a more formal response now.
Re: Coinbase user emails and full names leaked
#138This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails. Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same emai…
While that could be true, this list also includes the names; which would not be possible from what you're describing.
Re: Coinbase user emails and full names leaked
#139This is not a "leak". All of these email addresses were already in the wild. The "attacker" simply tested if Coinbase accounts matched these emails. Think about it. Email enumeration is possible if accounts associated with an email address. Otherwise forgot password forms would simply say successful even if someone typo'd their address (terrible UI) or the signup forms would allow multiple accounts with the same emai…
EDIT: On the other hand even if the response is always the same, I expect most implementations to be vulnerable to a timing attack ;)
Re: Coinbase user emails and full names leaked
#140Earlier quoted context omitted.
If you use gmail, you can use youremail+anything@gmail.com, and it will all get forwarded to youremail@gmail.com. This is incredibly handy for noticing who is sending you spam. I'll also use it for sites that I know are going to send me spam, and then immediately create a filter than deletes emails sent to joe+annoyingsite@gmail.com (note: that's not my real email)
Does this actually prevent true spammers, or only emails you consider spam, but the sender thinks is worthwhile? Otherwise, as a 'true' spammer, why wouldn't you just always strip off everything after the plus when adding the email to your distribution list?