Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

51–60 of 135 posts

Re: Update on Coinbase Data Security

#51

Earlier quoted context omitted.

They don't appear to be rate limiting their API that allows enumeration of first and last names. Also, We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinba…

Actually over a million: http://blog.coinbase.com/post/78016535692/a-major-coinbase-m...

That's wallets, not users. That press release was impressive, and I've always wondered how many users they actually had. I didn't expect to find out through a security blog post, but it's fun to know.

Re: Update on Coinbase Data Security

#52
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

Those systems are insured, and a lot more effort to steal and clean funds. Bitcoin is one stop fraud: get the coins and you're good to go. Don't need a drop to ship electronics, don't need proxies or remote desktop IPs to fool paypal/stripe fraud filters.

If I were a criminal blackhat would be nice to have user enumeration to confirm names on Coinbase so I could send personalized wallet stealing emails pretending to be from Coinbase.

Re: Update on Coinbase Data Security

#53
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

"It’s clear there was no data breach because no other user information is provided."

That strikes me as an assumption. There's no way for them to know that there was no breach based off of the fact that no other information was provided. There are other ways to know that you were not breached, this one comes across as a very weak / naive reason.

Re: Update on Coinbase Data Security

#54
post #14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

Not to make anything awkward, but this is a far better reply than Brian's replies in this thread and on the blog.

Re: Update on Coinbase Data Security

#55

Earlier quoted context omitted.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

Maybe in the US they don't, but in Canada you can. I'm quite sure in most of Europe & Australia you can as well.

Interac e-Transfers (the only widely used method for doing this I'm aware of) do let you send money to someone via an email address, but it's a notification channel, nothing more. An account enumeration isn't possible with it, the actual email is sent some time after the money for the transfer has left the source account, and the sender doesn't get any information about the delivery of the email.

I suppose you could send e-Transfers to random email addresses and then see if any are accepted, but that would cost you an absolute minimum of $0.01 per attempt and would probably have a terrible response rate.

Source: this is my day job.

Edit: sorry, forgot to mention this is Canada-specific.

Re: Update on Coinbase Data Security

#56
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

Respectfully, could you list a couple of benefits of enumerating a user's name if someone is requesting funds that outweigh the risk even in the slightest?

The question is not for sending money but receiving or requesting money. I personally can't think of a single benefit to getting this information at time of requesting funds.

As a matter of fact, if the name was enumerated when sending money that would to some (very small) degree be acceptable as the sender stood to have a financial loss.

edit: grammar

Re: Update on Coinbase Data Security

#57
(Bug report at https://hackerone.com/reports/5200)

From Ryan McGeehan, director of security (user magoo):

  > This behavior is mostly informational to an attacker and does not
  > directly increase risk in any significant way
All information leaks are useful to an attacker. By themselves they are harmless, but can be combined with other information to successfully exploit a system.

From bug reporter Shubham Shah (user zero):

  > This request can now be replayed unlimited times, with unlimited email
  > addresses inputted. Coinbase does not limit the rate of POST requests
  > to /transactions/request_money
This should not be possible at all. The reporter must have made a mistake and forgot to mention the X-CSRF-Token needs to be updated each time. If it didn't need to be updated, this would be a basic CSRF vuln.

All this being said, the real flaw here is the lack of rate limiting on transactions, for three reasons:

1. The spam will eventually mount up and ISPs will block their servers for days or weeks.

2. Their network and app stack is subject to DoS attacks unless they rate-limit transactions.

3. Harvesting of e-mail addresses would be stopped by basic rate limiting of emailuser queries.

Re: Update on Coinbase Data Security

#58
post #14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

What precautions have you taken against meatspace robbery? What's to stop 3 thugs with guns walking into your office(s) and cleaning out all the coins? Can you get insurance against this?

Do you also have measures to prevent evil janitor attacks like hardware keyloggers being planted at 4:00am? Do you have screens facing an open window to watch from across the street? Can I rent beside your offices, drill holes through the walls and set up spycams or gain entry? Not to sound alarmist but seems no exchange has given a thought to physical security meanwhile bank execs are dropped off at work by private guards specializing in counter-kidnapping operations, even though their money is fully insured and extremely difficult to steal. Bitcoin's are easy to steal.

Re: Update on Coinbase Data Security

#59
post #49

If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

[deleted]

Re: Update on Coinbase Data Security

#60
post #28
post #6

Earlier quoted context omitted.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Three-finger click on OS X defines the word. Or right-click and Look up in Dictionary.

Indeed, and a great trick too — but that appears to be a great but non-default option, only working within Apple software (namely Safari browser when surfing HN) and uses the System language (not English for me).

I personally prefer Right click “Search with Google…” in Chrome: it has the upside of coming up with a definition when the word is actually rare -- so it prevents me from defining an word I didn't know simply because I’m not a native English speaker.

Post reply on HN