Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

61–70 of 135 posts

Re: Update on Coinbase Data Security

#61
post #47
post #39

Earlier quoted context omitted.

For those of us getting caught up on these events - what evidence are you referring to? So far I've seen : 1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders 2) Homakov's email to whitehat@ concerning a potential iframe vuln What am I missing?

If I'm reading correctly: Coinbase provided confirmation that the email addresses on pastebin are Coinbase customers, and also provided the associated names. Coinbase doesn't think that's a serious issue.

[deleted]

Re: Update on Coinbase Data Security

#62
post #49

If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

they say the list is less than 0.5% of their total user base. Not sure if you can call this "large-scale".

Re: Update on Coinbase Data Security

#64
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

It is not my experience that financial services companies are substantially better than startups on cosmetic security issues like username enumeration.

Re: Update on Coinbase Data Security

#65

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

> For starters, of the 2042 "leaked" emails, 1153 are unique.

Nice observation. I hadn't noticed it at a glance.

> combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out.

I agree. Those are bold accusations, and bold accusations require at least some proof.

Re: Update on Coinbase Data Security

#66
post #49

If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

If you read the post even a little bit carefully, they refute the idea that this was a harvesting of their database. One compelling bit of evidence they present is that the list is tiny, and their customer list is very large.

It's not just that this isn't a "large scale" leak; it's that they say it's not a leak at all; that this data was made available through some other combination of services that exposed it, not Coinbase. They don't provide any additional evidence (but few companies would) --- but it's a plausible argument.

Re: Update on Coinbase Data Security

#69

I always find my ‘skeptic’ meter ticks faster when I read of a data breach, and find a company: a) using language that is very specific when making a denial b) also introducing a new Director of Security in the same post

No new director was introduced; the Ryan McGeehan hire was in the news weeks ago.

Re: Update on Coinbase Data Security

#70

>there has been no data breach of names or emails at Coinbase I have a Pastebin URL with 200 email addresses to prove the contrary. Why lie in PR?

You have to have the email addresses before you can query Coinbase with them. The addresses didn't originate with Coinbase, the attacker already had them.
Post reply on HN