Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

31–40 of 135 posts

Re: Update on Coinbase Data Security

#32

No mention of the claimed IRS / Fed gag order, interesting. (although I realize its not their main focus right now)

Well they can't mention it if they have it, but they can mention if they don't. So this would be the only way Coinbase could communicate that they are under a gag order, barring a prior warrant canary. So it's probably prudent to act as if they have acknowledged the gag order until they deny it. Although it'd be really dumb if anyone was assuming the records were private.

I guess they could say "We have implemented a warrant canary at " then 404, but perhaps their legal team wisely denied that one.

Re: Update on Coinbase Data Security

#33
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

You conveniently left out their next sentence "... many leading payment services allow user enumeration, including Paypal, Venmo, Square Cash, and many others..."

Re: Update on Coinbase Data Security

#34
post #19
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

This is something that has always bothered me. I've worked in software for awhile now, but never in the financial sector, yet the vast majority of my clients and employers have had third party security audits run on their code and systems. I don't know why every exchange doesn't do this and talk about it publicly.

Everyone in the biz or following the biz knows its window dressing and pay to play. See Arthur Anderson and Enron and about a zillion other scandals over the years.

Re: Update on Coinbase Data Security

#35

Earlier quoted context omitted.

They don't appear to be rate limiting their API that allows enumeration of first and last names. Also, We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinba…

The list duplicates every entry, probably another silly tactic by the "attacker" to fluff up his feathers.

I wonder if that means there are around 200,000 Coinbase users? Depends whether they noticed the dupes. Good catch.

Re: Update on Coinbase Data Security

#36
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

'We didn't do anything wrong, this isn't a bug, nothing to see here.' despite obvious evidence to the contrary.

Very confidence inducing.

Re: Update on Coinbase Data Security

#37
post #33
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

You conveniently left out their next sentence "... many leading payment services allow user enumeration, including Paypal, Venmo, Square Cash, and many others..."

Because I was talking about banks & processors, not payment services. Paypal will cut you off hard if you attempt to bulk enumerate users/businesses by e-mail address, so this is even more disingenuous on the part of Coinbase.

Re: Update on Coinbase Data Security

#38
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

Coinbase has had a substantial Whitehat program for a while: https://coinbase.com/whitehat

This just isn't a bug.

Re: Update on Coinbase Data Security

#39
post #36
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

'We didn't do anything wrong, this isn't a bug, nothing to see here.' despite obvious evidence to the contrary. Very confidence inducing.

For those of us getting caught up on these events - what evidence are you referring to?

So far I've seen :

1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders

2) Homakov's email to whitehat@ concerning a potential iframe vuln

What am I missing?

Re: Update on Coinbase Data Security

#40
While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out.

Enumeration isn't a fantastic idea, but given its ubiquity in various forms on major sites throughout the internet, I don't think it's worthy of all of this negative attention directed specifically at Coinbase either. I once wrote a program that could take a list of random emails and use Facebook to turn it into a CSV matching each email to a name, a list of their friends, their location, and interests. That should have been scandalous, but it wasn't.

We are acting as pawns in someone's revenge scheme against Coinbase.

Post reply on HN