Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

21–30 of 135 posts

Re: Update on Coinbase Data Security

#21
You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site.

And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

Re: Update on Coinbase Data Security

#22
post #14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

Thanks for coming here and addressing the community. It's a thankless job. But thank you for doing it.

Re: Update on Coinbase Data Security

#23
post #14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

Further, the security audit began this week before this issue. It was proactive, not responsive.

Re: Update on Coinbase Data Security

#24
post #6
post #2

Less sympathetic than I was hoping for but copacetic. Could they have nipped this in the bud with a faster response? Perhaps. However having dealt with reports like this, I cannot recall a decent interaction with a reporter.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Many people automatically assume that this word means something bad. Something about "cetic" makes them think "septic" or "toxic" even. I've had to explain the word a few times to co-workers. I picked it up from a crappy song, come on guys!

Re: Update on Coinbase Data Security

#25
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others.

The reason you don't see it with banks is that they don't allow you to send money to an email address.

Re: Update on Coinbase Data Security

#26
post #4

Earlier quoted context omitted.

From the text: "For example, we employ rate limits around sensitive actions, such as requesting money, to prevent them from being abused at scale."

They don't appear to be rate limiting their API that allows enumeration of first and last names. Also, We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinba…

The list duplicates every entry, probably another silly tactic by the "attacker" to fluff up his feathers.

Re: Update on Coinbase Data Security

#27
I don't who is wrong or right here (Coinbase saying there was no breach or alledged hackers via pastebin), but isn't having fake security breaches for large bitcoin sites a good opportunity to manipulate the rates? If one wanted to bring the rate down it might be possible to do this with creating a good fake security breach of a large site.

Re: Update on Coinbase Data Security

#28
post #6
post #2

Less sympathetic than I was hoping for but copacetic. Could they have nipped this in the bud with a faster response? Perhaps. However having dealt with reports like this, I cannot recall a decent interaction with a reporter.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Three-finger click on OS X defines the word. Or right-click and Look up in Dictionary.

Re: Update on Coinbase Data Security

#29
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

Maybe in the US they don't, but in Canada you can. I'm quite sure in most of Europe & Australia you can as well.
Post reply on HN