Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

231–240 of 294 posts

Re: Coinbase user emails and full names leaked

#232

Earlier quoted context omitted.

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

Not saying it was a good reason. Just that they did address the question.

http://blog.shubh.am/full-disclosure-coinbase-security/

According to the original researcher, he mailed them and got no response, and got no response at all from several other attempts at contact,.

I wouldn't be surprised one bit to find that the inbox for that address is full of spam and crackpots, but, like 'tptacek said, if you're going to have the list you had better dedicate resources to reading it.

Re: Coinbase user emails and full names leaked

#233
post #105

Earlier quoted context omitted.

There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.

I work on dating sites, some of them a bit risqué. On the password reset form, there's a big difference between saying "That email does not exist in our system"/"Emailed password reset instructions" vs "If that account is registered, we will email you instructions".

Do you setup a timed sleep to make sure that you return results in exactly the same time regardless of path taken?

Re: Coinbase user emails and full names leaked

#235
post #180

I got two requests already. What kinda morons works at Coinbase to allow this?

They're now "morons" to allow people to send payment requests? Perhaps you're not quite familiar with their business model.

Also, allowing people to use accounts from recyclable email services such as "mailinator" is another design flaw. There are bunch of projects that maintain a list of those as far as I recall.

Re: Coinbase user emails and full names leaked

#236
post #170

Earlier quoted context omitted.

Read this: http://www.irs.gov/Businesses/Small-Businesses-&-Self-Employ... "An audit may be conducted by mail or through an in-person interview and review of the taxpayer's records." "You will be provided with a written request for specific documents needed." "An IRS audit is a review/examination of an organization's or individual's accounts and financial information to ensure information is being reported correctly,…

Could we just say that it's not what people usually think of when they say "IRS audit"? Getting a letter in the mail asking for some paperwork isn't really scary.

I'd imagine a letter in the mail asking for some paperwork is pretty terrifying if you have been cheating on your taxes. :)

Re: Coinbase user emails and full names leaked

#237
post #10

Earlier quoted context omitted.

You're right. As a Coinbase customer, neither my name or Coinbase-only email address was in this list. What you describe is exactly the exploit that was disclosed and exactly what the person exploiting it seems to have done based on the content of the list. Of course, Coinbase argues that this is a feature and not a bug.

> neither my name or Coinbase-only email address was in this list That doesn't really mean anything, since it clearly says at the top: "Here is a partial list of Coinbase user emails and their full names. Full list much bigger." Which could be bullshit and scaremongering. But it certainly could be true that they have a large number of Coinbase user's emails.

>Which could be bullshit and scaremongering.

It could also be that you are reading too much into it.

>"Here is a partial list of Coinbase user emails and their full names. Full list much bigger."

Where does it say in that sentence that he the OP has access to the "full list"? It doesn't say that. It implies it, which you picked right up on. But he doesn't explicitly say, "Here is a partial list of the full list in my possession".

Re: Coinbase user emails and full names leaked

#238

Earlier quoted context omitted.

I work on dating sites, some of them a bit risqué. On the password reset form, there's a big difference between saying "That email does not exist in our system"/"Emailed password reset instructions" vs "If that account is registered, we will email you instructions".

Do you setup a timed sleep to make sure that you return results in exactly the same time regardless of path taken?

Not sure if sarcasm..

Re: Coinbase user emails and full names leaked

#239

I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…

To be clear, the attacker got your email from somewhere else and confirmed that it was on Coinbase. That's the "bug." It's like if you went to go make an account with a certain email on Facebook and found that it was taken. You would then know that the person with that email has an account on Facebook. Regarding user names, they are optional and meant to be public. I think the biggest problem here has been that Coinb…

Im sceptical of this. My email was not published anywhere with regards to bitcoin or coinbase, I receive relatively little spam, yet I received 4 of these messages.

Re: Coinbase user emails and full names leaked

#240

Earlier quoted context omitted.

I haven't really lost my trust in Coinbase due to this issue but I do find it annoying the way they are handling it so far. Almost any site that has a password reset can be used to verify whether an email account exists in that system - depending if the system tells you "no user with that username exists" or not. Coinbase is in no way unique with the amount of info they expose, which is the point they were trying to…

It is certainly possible to allow for password resets and account creation as well without revealing whether an account exists. Password reset: 1. User enters email in password reset form. 2. Website shows the same message whether the password was reset or not. 3. Email is what differs. If the account exists, send a password reset link. If it does not, send an email asking them if they want to create an account (and…

Yes, this is the right workflow, but, you'll be surprised how very few services implement this properly! Another thing that most services don't implement is providing geolocation and other pieces of info in password reset emails and the ability to report that you didn't request that with some basic flagging (even as simple as flagging that session), which would prevent that guy of keep resetting it. The ability to add login email notification is also priceless.
Post reply on HN