Earlier quoted context omitted.
If you use gmail, you can use youremail+anything@gmail.com, and it will all get forwarded to youremail@gmail.com. This is incredibly handy for noticing who is sending you spam. I'll also use it for sites that I know are going to send me spam, and then immediately create a filter than deletes emails sent to joe+annoyingsite@gmail.com (note: that's not my real email)
Does this actually prevent true spammers, or only emails you consider spam, but the sender thinks is worthwhile? Otherwise, as a 'true' spammer, why wouldn't you just always strip off everything after the plus when adding the email to your distribution list?
Coinbase user emails and full names leaked
181–190 of 294 posts
Re: Coinbase user emails and full names leaked
#182Earlier quoted context omitted.
How would they be vulnerable to a timing attack?
Sending an email takes more time than not sending an email.
Re: Coinbase user emails and full names leaked
#183Earlier quoted context omitted.
I've used sneakemail for a number of years. With their paid account ($12/yr, I think), it lets you create emails on the fly with a specific pattern. For example: amazon-flanbiscuit@sneakemail.com That gets forwarded to your actual email address, and you can see how it was tagged. If needed, you can whitelist/blacklist specific senders from specific tags as well.
With any standards compliant email server you can use "+whatever" in the username and the email should get to you: username+whatever@example.com.
Re: Coinbase user emails and full names leaked
#184Earlier quoted context omitted.
They mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason
Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.
Not just emails, either. See also event logging: https://www.schneier.com/blog/archives/2014/03/details_of_th...
Re: Coinbase user emails and full names leaked
#185I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…
Regarding user names, they are optional and meant to be public.
I think the biggest problem here has been that Coinbase hasn't been responsive to messages sent to their whitehat@ address. That and the fact that users are being spammed by "researchers," which is a problem that falls back on them to mitigate.
They haven't been "hacked" though, and the only thing that has been "leaked" is public account names and account existence. The latter is almost impossible to avoid if you require unique emails for accounts (if I'm wrong about that please correct me).
That's just my naive two cents, so let me know where I'm missing the picture if that's the case! :)
Re: Coinbase user emails and full names leaked
#186Earlier quoted context omitted.
MtGox was the biggest Bitcoin exchange with the largest trade volume. I still lost all my BTC when it went under.
Same. It seems like it can't happen until it happens, and then you face the reality that it happened. It sucks, and there's absolutely no protection for consumers from it. There's not even any insurance policy that exchanges can purchase yet, which is pretty much the only hope at this point.
Re: Coinbase user emails and full names leaked
#187Relatedly: DO NOT CHEAT ON YOUR TAXES. If you have any BTC profits and do not report them to the IRS this month, they are reasonably likely to catch you and make an example of you.
YOU ARE WRONG. The IRS is .1% in the business of audits and 99.9% in the business of scaring people about the possibility of an audit. Like you just did.
Re: Coinbase user emails and full names leaked
#188Earlier quoted context omitted.
It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…
2 things: First, the vast majority of attackers are more "smash and grab" than "stealthy jewel theft." They really don't care about leaving tracks, they are going for volume. Want to phish people for coinbase creds? Email a mass of people. Have a list of usernames/password from a data breach? Attackers have automated tools that will automatically try them against thousands of websites. It's more expensive and time co…
But if you know somebody has a lot of money, then the rational amount of effort to apply goes way up. That's why stealthy jewel thieves are stealthy.
Since the whole point of Coinbase is to contain money that, from other BTC sites, appears to be easily stolen and easily laundered, I think a set of known Coinbase accounts could well be worth the effort.
Re: Coinbase user emails and full names leaked
#189Earlier quoted context omitted.
That won't help here, your real Gmail address is exposed which lets everyone know that you have BTC on web wallets.
Actually it would help you here. In this case your real address isn't exposed unless someone guessed the exact version you used to sign up.
Re: Coinbase user emails and full names leaked
#190Earlier quoted context omitted.
I've used sneakemail for a number of years. With their paid account ($12/yr, I think), it lets you create emails on the fly with a specific pattern. For example: amazon-flanbiscuit@sneakemail.com That gets forwarded to your actual email address, and you can see how it was tagged. If needed, you can whitelist/blacklist specific senders from specific tags as well.
With any standards compliant email server you can use "+whatever" in the username and the email should get to you: username+whatever@example.com.
That functionality is not an RFC requirement, however.