Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

241–250 of 294 posts

Re: Coinbase user emails and full names leaked

#241
post #98
post #78

Someone should market bitcoin to women. From a cursory review of that list of names, women don't seem to be signing up. Missing half the market...

Some members of the Bitcoin community have... some work to do in making women feel welcome. An illustrative blog post by a woman that went to a meetup: http://www.ariannasimpson.com/this-is-what-its-like-to-be-a-... “Well,” he says looking at me knowingly, “Women don’t usually think in terms of efficiency and effectiveness”.

ugh. that's so horrible.

Re: Coinbase user emails and full names leaked

#242
post #59
post #36

Earlier quoted context omitted.

It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…

I would argue that using a personal email and filling in your full name on coinbase, who CLEARLY state you have no expectation of privacy in this regard, is effectively the same as publicizing the information. If one cares about the privacy aspect, then don't use an email that is tied back to you in any way, and certainly don't fill in your personal information.

[deleted]

Re: Coinbase user emails and full names leaked

#243

Earlier quoted context omitted.

I haven't really lost my trust in Coinbase due to this issue but I do find it annoying the way they are handling it so far. Almost any site that has a password reset can be used to verify whether an email account exists in that system - depending if the system tells you "no user with that username exists" or not. Coinbase is in no way unique with the amount of info they expose, which is the point they were trying to…

It is certainly possible to allow for password resets and account creation as well without revealing whether an account exists. Password reset: 1. User enters email in password reset form. 2. Website shows the same message whether the password was reset or not. 3. Email is what differs. If the account exists, send a password reset link. If it does not, send an email asking them if they want to create an account (and…

I agree 100% this is the right way to do it. And it's really not any more difficult to implement.

The problem is the convenience tradeoff. Take a site that has an instant green/red indicator that a username is already taken. People love the instant feedback, but it creates an attack vector. If you had to wait around for an email to see if you had already signed up - I bet a "Show HN" would have people here telling you that your site was user hostile! Even though it is unquestionably more secure.

I do think what Coinbase is doing now is not out of line with standard practices. But for a financial site they might be wise to start erring in the direction of security at the expense of a little convenience.

Re: Coinbase user emails and full names leaked

#244

Earlier quoted context omitted.

Wouldn't that add a transactional cost to bitcoin, not unlike PayPal or Visa?

I've spent a couple months trying to come up with ways to protect bitcoin consumers, and the only thing I can think of is for exchanges to purchase some kind of high-risk insurance which will cover losses by the exchange. Nothing else will protect users, as far as I can tell, precisely because of bitcoin's irreversible transactions. Honestly, the best thing for the bitcoin ecosystem is to learn from Paypal and Visa,…

Well, you could create a certification program in which member exchanges agree to a set of financial standards between each other - e.g. they would automatically do charge backs on disputes within the system.

This could lower the transactional-risk cost between doing business with certified exchanges, and still allow users to do business outside but with the increased transactional costs.

But then again you're just building another financial exchange system controlled by the certificate issuer - except it would need to be backed by some form of international enforcement (e.g. WTO?).

Where is the benefit to bitcoins then?

Re: Coinbase user emails and full names leaked

#245

Earlier quoted context omitted.

They mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

They're actually downright expensive addresses to maintain, and they don't cost tech support cycles, they cost security engineer time.

A basic tech support person might be able to fend off the dozens of word salad "security notifications" sent by ESL students, but as they get more complicated and no less often irrelevant, you need people who actually know how your infrastructure works.

On top of the technical hassle comes the customer experience hassle of keeping a bunch of wanna be hackers happy as they demand rewards and their name on your site for their idea of a CRSF vulnerability that happens to have no basis in reality.

Re: Coinbase user emails and full names leaked

#246

Earlier quoted context omitted.

To be clear, the attacker got your email from somewhere else and confirmed that it was on Coinbase. That's the "bug." It's like if you went to go make an account with a certain email on Facebook and found that it was taken. You would then know that the person with that email has an account on Facebook. Regarding user names, they are optional and meant to be public. I think the biggest problem here has been that Coinb…

Im sceptical of this. My email was not published anywhere with regards to bitcoin or coinbase, I receive relatively little spam, yet I received 4 of these messages.

The original disclosure never claimed that emails were leaked. They were found somewhere else: http://blog.shubh.am/full-disclosure-coinbase-security/#poc

Their official response confirms this: http://blog.coinbase.com/post/81407694500/update-on-coinbase...

Re: Coinbase user emails and full names leaked

#247

Earlier quoted context omitted.

Do you setup a timed sleep to make sure that you return results in exactly the same time regardless of path taken?

Not sure if sarcasm..

This is a real attack vector. It's called a timing attack: http://en.wikipedia.org/wiki/Timing_attack

Re: Coinbase user emails and full names leaked

#248

Earlier quoted context omitted.

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

They're actually downright expensive addresses to maintain, and they don't cost tech support cycles, they cost security engineer time. A basic tech support person might be able to fend off the dozens of word salad "security notifications" sent by ESL students, but as they get more complicated and no less often irrelevant, you need people who actually know how your infrastructure works. On top of the technical hassle…

The backlash against these aliases is perceptible, but remember that the worst-case scenarios we're talking about today, when those addresses aren't properly staffed, was the default case before they became a common feature of startups.

Re: Coinbase user emails and full names leaked

#249
post #247

Earlier quoted context omitted.

Not sure if sarcasm..

This is a real attack vector. It's called a timing attack: http://en.wikipedia.org/wiki/Timing_attack

I am familiar with timing attacks. The thought of someone attempting to apply it over the internet to verify whether an email is registered on a dating site seems laughable.
Post reply on HN