Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

181–190 of 294 posts

Re: Coinbase user emails and full names leaked

#181

Earlier quoted context omitted.

If you use gmail, you can use youremail+anything@gmail.com, and it will all get forwarded to youremail@gmail.com. This is incredibly handy for noticing who is sending you spam. I'll also use it for sites that I know are going to send me spam, and then immediately create a filter than deletes emails sent to joe+annoyingsite@gmail.com (note: that's not my real email)

Does this actually prevent true spammers, or only emails you consider spam, but the sender thinks is worthwhile? Otherwise, as a 'true' spammer, why wouldn't you just always strip off everything after the plus when adding the email to your distribution list?

Depends on how smart the spammer is, and how much they care. Most spammers a) are not very bright, and b) are in a volume business. Even the ones smart enough to do this may not think it worth the time to possibly improve a tiny percentage of harvested addresses. Especially since those of us who are dedicated enough to maintain tagged addresses are unlikely to respond positively to spam no matter what address we receive it on.

Re: Coinbase user emails and full names leaked

#182
post #173

Earlier quoted context omitted.

How would they be vulnerable to a timing attack?

Sending an email takes more time than not sending an email.

I think I see your point; clever. The site could show the message and only then send the mail asynchronously. I guess that's why you said most implementations.

Re: Coinbase user emails and full names leaked

#183

Earlier quoted context omitted.

I've used sneakemail for a number of years. With their paid account ($12/yr, I think), it lets you create emails on the fly with a specific pattern. For example: amazon-flanbiscuit@sneakemail.com That gets forwarded to your actual email address, and you can see how it was tagged. If needed, you can whitelist/blacklist specific senders from specific tags as well.

With any standards compliant email server you can use "+whatever" in the username and the email should get to you: username+whatever@example.com.

I believe that totally depends on the mail server. If there is an actual standard for that, please do point me to it.

Re: Coinbase user emails and full names leaked

#184

Earlier quoted context omitted.

They mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

Cheap, sure, but they'll cost you plenty in "lost face" when we journos write that you ignored inbound alerts from the person who later published something out of frustration.

Not just emails, either. See also event logging: https://www.schneier.com/blog/archives/2014/03/details_of_th...

Re: Coinbase user emails and full names leaked

#185

I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…

To be clear, the attacker got your email from somewhere else and confirmed that it was on Coinbase. That's the "bug." It's like if you went to go make an account with a certain email on Facebook and found that it was taken. You would then know that the person with that email has an account on Facebook.

Regarding user names, they are optional and meant to be public.

I think the biggest problem here has been that Coinbase hasn't been responsive to messages sent to their whitehat@ address. That and the fact that users are being spammed by "researchers," which is a problem that falls back on them to mitigate.

They haven't been "hacked" though, and the only thing that has been "leaked" is public account names and account existence. The latter is almost impossible to avoid if you require unique emails for accounts (if I'm wrong about that please correct me).

That's just my naive two cents, so let me know where I'm missing the picture if that's the case! :)

Re: Coinbase user emails and full names leaked

#186

Earlier quoted context omitted.

MtGox was the biggest Bitcoin exchange with the largest trade volume. I still lost all my BTC when it went under.

Same. It seems like it can't happen until it happens, and then you face the reality that it happened. It sucks, and there's absolutely no protection for consumers from it. There's not even any insurance policy that exchanges can purchase yet, which is pretty much the only hope at this point.

xapo.com is insured by Meridian group. There's also one in the UK that's insured Lloyd's that I'm drawing a blank on. Have you looked into either of them?

Re: Coinbase user emails and full names leaked

#187
post #82

Relatedly: DO NOT CHEAT ON YOUR TAXES. If you have any BTC profits and do not report them to the IRS this month, they are reasonably likely to catch you and make an example of you.

YOU ARE WRONG. The IRS is .1% in the business of audits and 99.9% in the business of scaring people about the possibility of an audit. Like you just did.

Keep in mind that they don't have to do this this year - they have 7 years to catch you evading tax in 2013.

Re: Coinbase user emails and full names leaked

#188
post #36

Earlier quoted context omitted.

It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…

2 things: First, the vast majority of attackers are more "smash and grab" than "stealthy jewel theft." They really don't care about leaving tracks, they are going for volume. Want to phish people for coinbase creds? Email a mass of people. Have a list of usernames/password from a data breach? Attackers have automated tools that will automatically try them against thousands of websites. It's more expensive and time co…

That first point strikes me as irrelevant here. Smash and grab is what you do when your probability of success and/or your take size is small.

But if you know somebody has a lot of money, then the rational amount of effort to apply goes way up. That's why stealthy jewel thieves are stealthy.

Since the whole point of Coinbase is to contain money that, from other BTC sites, appears to be easily stolen and easily laundered, I think a set of known Coinbase accounts could well be worth the effort.

Re: Coinbase user emails and full names leaked

#189
post #163

Earlier quoted context omitted.

That won't help here, your real Gmail address is exposed which lets everyone know that you have BTC on web wallets.

Actually it would help you here. In this case your real address isn't exposed unless someone guessed the exact version you used to sign up.

What do you mean? If joeblow+coinbase@gmail.com is in the leaked list you know that that joeblow@gmail.com is the "real" user and also is someone who has BTC.

Re: Coinbase user emails and full names leaked

#190

Earlier quoted context omitted.

I've used sneakemail for a number of years. With their paid account ($12/yr, I think), it lets you create emails on the fly with a specific pattern. For example: amazon-flanbiscuit@sneakemail.com That gets forwarded to your actual email address, and you can see how it was tagged. If needed, you can whitelist/blacklist specific senders from specific tags as well.

With any standards compliant email server you can use "+whatever" in the username and the email should get to you: username+whatever@example.com.

"+" is valid in the left-hand side portion and Postfix uses it (by default) as the separator to provide this feature but other mail systems (Qmail and, IIRC, Courier) use "-".

That functionality is not an RFC requirement, however.

Post reply on HN