Is there an option to opt your account info OUT of the api?
Update on Coinbase Data Security
31–40 of 135 posts
Re: Update on Coinbase Data Security
#32No mention of the claimed IRS / Fed gag order, interesting. (although I realize its not their main focus right now)
I guess they could say "We have implemented a warrant canary at " then 404, but perhaps their legal team wisely denied that one.
Re: Update on Coinbase Data Security
#33You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
Re: Update on Coinbase Data Security
#34I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…
This is something that has always bothered me. I've worked in software for awhile now, but never in the financial sector, yet the vast majority of my clients and employers have had third party security audits run on their code and systems. I don't know why every exchange doesn't do this and talk about it publicly.
Re: Update on Coinbase Data Security
#35Earlier quoted context omitted.
They don't appear to be rate limiting their API that allows enumeration of first and last names. Also, We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinba…
The list duplicates every entry, probably another silly tactic by the "attacker" to fluff up his feathers.
Re: Update on Coinbase Data Security
#36You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
Very confidence inducing.
Re: Update on Coinbase Data Security
#37You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
You conveniently left out their next sentence "... many leading payment services allow user enumeration, including Paypal, Venmo, Square Cash, and many others..."
Re: Update on Coinbase Data Security
#38I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…
This just isn't a bug.
Re: Update on Coinbase Data Security
#39You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
'We didn't do anything wrong, this isn't a bug, nothing to see here.' despite obvious evidence to the contrary. Very confidence inducing.
So far I've seen :
1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders
2) Homakov's email to whitehat@ concerning a potential iframe vuln
What am I missing?
Re: Update on Coinbase Data Security
#40Enumeration isn't a fantastic idea, but given its ubiquity in various forms on major sites throughout the internet, I don't think it's worthy of all of this negative attention directed specifically at Coinbase either. I once wrote a program that could take a list of random emails and use Facebook to turn it into a CSV matching each email to a name, a list of their friends, their location, and interests. That should have been scandalous, but it wasn't.
We are acting as pawns in someone's revenge scheme against Coinbase.