Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

141–150 of 294 posts

Re: Coinbase user emails and full names leaked

#141

Earlier quoted context omitted.

It keeps phishing attacks from being able to cross services (since if you get a citibank email to your coinbase email that would be a big flag) and it reduces the attack surface on other sites. I use email.site@domain.com for this purpose and it makes it handy to see who has somehow lost/disclosed my email to third parties and not informed me (FreshDirect for example)

email.site@domain.com is at least a distinct email address, unlike using +. Especially if you use different passwords for each account, it means if one of the emails is compromised then the attacker can't use it to recover passwords of your other sites.

+ can be a distinct email address, just as . can be an alias. It really depends on how your email server is configured. Postfix makes it really easy to adjust what character you use.

Re: Coinbase user emails and full names leaked

#143

Earlier quoted context omitted.

That does nothing to increase the security of your accounts, since effectively the email address is the same.

It keeps phishing attacks from being able to cross services (since if you get a citibank email to your coinbase email that would be a big flag) and it reduces the attack surface on other sites. I use email.site@domain.com for this purpose and it makes it handy to see who has somehow lost/disclosed my email to third parties and not informed me (FreshDirect for example)

> It keeps phishing attacks from being able to cross services (since if you get a citibank email to your coinbase email that would be a big flag) and it reduces the attack surface on other sites.

Or, more importantly, it lets you authenticate the sender in some way. Citibank has to send you email to you.citibankiscool1253stuffonlyIknow@example.net and it is unlikely for a spammer to guess that exact wording (without also trying hundreds of others, which would give it away by filling your inbox).

Re: Coinbase user emails and full names leaked

#144
post #137

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.

Would you include in your response the reason why you're ignoring Homakov's security flaw reports, which were emailed to you at your whitehat@coinbase.com email address?

https://news.ycombinator.com/item?id=7505757

A lot of people are getting nervous that you're not taking security seriously at Coinbase. Ignoring whitehat reports would seem to be a serious issue.

Re: Coinbase user emails and full names leaked

#146
I contacted Coinbase and received this response:

Erik: Our engineers are aware of this development and concluded that the released information was not acquired through a security breach in our systems. Instead, the poster was already in possession of your email address and used our "Request Money" functionality to obtain the name given to our system on the Settings page of your account (https://coinbase.com/settings). Although this is an intended feature, we understand that some users may wish to not disclose information to third-parties that are able to obtain their email addresses. As such, we are working on improvements that will give users an option to hide their name from other users.

Re: Coinbase user emails and full names leaked

#147

Earlier quoted context omitted.

Does this actually prevent true spammers, or only emails you consider spam, but the sender thinks is worthwhile? Otherwise, as a 'true' spammer, why wouldn't you just always strip off everything after the plus when adding the email to your distribution list?

I use _, not "+" and anybody else might use "." or "-" depending on the configuration of their mail server. Sure, you can always add the full email and every possible stripped email to your lists, but in practice, few people seem to do that (judging by the amount of spam I get to me_randomstuff@example.net as compared to me@example.net).

I use "-" with an alias to "_". It turns out that when you give an email address to random people, they sometimes don't know the difference between "dash" or "hyphen" and an underscore.

Re: Coinbase user emails and full names leaked

#148

Earlier quoted context omitted.

I may be missing something but your link is 301'ing to http://support.coinbase.com/customer/portal/emails/new so I really don't how I can submit a contact form over SSL. It is kind of a moot point because I have committed to moving my bitcoin out of coinbase.

Strange. No 301 here. http://i.imgur.com/2eWQ2kP.png

Odd - if I go to https://support.coinbase.com/customer/portal/emails/new I get an untrusted connection warning since the SSL certificate is for *.desk.com, not support.coinbase.com.

Re: Coinbase user emails and full names leaked

#149
post #131
post #72

Earlier quoted context omitted.

You can only get so much for FREE, that's not Coinkite.com's model. We charge, but we answer email and fix issues.

But a quick read over your ToS defines bitcoins as having no value and not subject to law ("Bitcoins and Litecoins ("Coins") do not constitute a currency, an asset or a form of property at law or otherwise") and that you're not responsible if they mysteriously vanish ("Any purchase or sale of Coins, for money, virtual currency or other consideration, involves inherent risks and may lead to the complete loss of any va…

Yes, but they'll answer e-mails when you ask why all of your bitcoins disappeared.

Re: Coinbase user emails and full names leaked

#150
post #128

Earlier quoted context omitted.

You're right, of course, and maybe I should have said "nothing wrong with submitting an article to hn without putting an established identity or even your real-life personal safety on the line". I suppose it was my desire to express with that comment my wider frustration regarding stuff like facebook/google+ real name policies that made my opt for a less accurate statement.

In general I agree, although there are certainly times when anonymity could be problematic even submitting an article on HN - for example, lying about an individual or a company, or starting a dangerous rumor. The benefit of anonymity is, generally, to protect the anonymous from retaliation for things said or done anonymously. This is important, priceless even, when evil is being done by the powerful. For example, wh…

The comment I was responding to seemed like a blanket condemnation of anonymous submissions, so I felt like a blanket rejection of that statement was in order. With regards to protecting whistleblowing versus people starting dangerous rumors, I think we can safely err towards accepting anonymous submissions without scrutiny since the community is already fairly skeptical.

I don't feel compelled to sympathize with Facebook/Google+'s business cases. I'm not criticizing their business acumen, after all.

Post reply on HN