Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

151–160 of 294 posts

Re: Coinbase user emails and full names leaked

#151
post #76

At this point I would not trust Coinbase, their engineering department shows that they have very little clue when it comes to building a secure infrastructure. Not only they are not rate limiting and leaking names, their implementations are simply laughable. With a proper design, customer should have been allowed to either enable/disable that end-point when somebody is searching for their email, or there should have…

I haven't really lost my trust in Coinbase due to this issue but I do find it annoying the way they are handling it so far.

Almost any site that has a password reset can be used to verify whether an email account exists in that system - depending if the system tells you "no user with that username exists" or not. Coinbase is in no way unique with the amount of info they expose, which is the point they were trying to make on their "official" response.

I would have liked to see them announce that the API does have some sort of throttle and maybe they are going to think of ways to enable an option for this behavior or something - basically anything except to just dismiss it. Because even though I personally agree with them as far as the level of vulnerability - a lot of people don't and Coinbase doesn't seem to understand this perception problem.

Re: Coinbase user emails and full names leaked

#152

Earlier quoted context omitted.

Strange. No 301 here. http://i.imgur.com/2eWQ2kP.png

Odd - if I go to https://support.coinbase.com/customer/portal/emails/new I get an untrusted connection warning since the SSL certificate is for *.desk.com, not support.coinbase.com.

That's not odd. That's why I linked to https://coinbase.desk.com since he wanted SSL.

Re: Coinbase user emails and full names leaked

#153

Earlier quoted context omitted.

how do you keep track of all the emails? and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

I've used sneakemail for a number of years. With their paid account ($12/yr, I think), it lets you create emails on the fly with a specific pattern. For example: amazon-flanbiscuit@sneakemail.com That gets forwarded to your actual email address, and you can see how it was tagged. If needed, you can whitelist/blacklist specific senders from specific tags as well.

With any standards compliant email server you can use "+whatever" in the username and the email should get to you: username+whatever@example.com.

Re: Coinbase user emails and full names leaked

#154
post #137

Earlier quoted context omitted.

Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.

Would you include in your response the reason why you're ignoring Homakov's security flaw reports, which were emailed to you at your whitehat@coinbase.com email address? https://news.ycombinator.com/item?id=7505757 A lot of people are getting nervous that you're not taking security seriously at Coinbase. Ignoring whitehat reports would seem to be a serious issue.

They mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason

Re: Coinbase user emails and full names leaked

#155
post #59
post #36

Earlier quoted context omitted.

It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…

I would argue that using a personal email and filling in your full name on coinbase, who CLEARLY state you have no expectation of privacy in this regard, is effectively the same as publicizing the information. If one cares about the privacy aspect, then don't use an email that is tied back to you in any way, and certainly don't fill in your personal information.

Or, and this is much easier, use a web site that actually cares about its users' privacy?

If CoinBase is so needlessly sloppy then it's not hard to picture a Mt Goxish scenario in its future.

Re: Coinbase user emails and full names leaked

#156
post #105

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.

That sounds innocuous. But it's easy for, say, mobile badware to harvest contact lists. By targeting non-anonymous bitcoin holders as a "seed" list and using exposed contact lists like LinkedIn contacts, you can ratchet your way up into disclosing a lot of people who would prefer not to be known, lest the become phishing targets.

Doesn't seem innocuous. Maybe coinbase ought to be making pseudonymity more easily accessible.

Re: Coinbase user emails and full names leaked

#157
post #105

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.

It gives the full name associated with an email address. A more dramatic but analogous situation would be if an attacker were able to attain password info or credit card info associated with an email address.

Just because email address is known does not imply that other personal information should be given away.

Re: Coinbase user emails and full names leaked

#158
post #44

And this is why in addition to per site passwords, I also use per site email addresses. I like to be able to track who spams me and in case of leaks I like the ability to disable an email address...

how do you keep track of all the emails? and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

Microsoft email ( outlook.com ) offers email aliases which are pretty good for this purpose .

Re: Coinbase user emails and full names leaked

#159
post #137

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.

Then how am I on the list with an email I only use at coinbase? With my full email and name, and i'm getting spammed non-stop by this "non-important" security flaw in your system.. multiple times today and counting.

Re: Coinbase user emails and full names leaked

#160
post #2

The link has no mention of the "bug was dismissed" as stated in the HN title. Support for this? Or is it the same bug as https://news.ycombinator.com/item?id=7504353 ? Also, what is the evidence for the assertion that transaction logs are delivered daily? Given recent revelations, it's probably a reasonable assumption, but there's still no actual evidence given.

Here is the reporter finally resorting to full disclosure after having tried repeatedly to reach out to Coinbase without getting any response at all: http://blog.shubh.am/full-disclosure-coinbase-security/
Post reply on HN