Update on Coinbase Data Security
71–80 of 135 posts
Re: Update on Coinbase Data Security
#72does anyone know what blogging software they are using for the coinbase blog? is it tumblr?
Re: Update on Coinbase Data Security
#73While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…
> For starters, of the 2042 "leaked" emails, 1153 are unique.
Sure enough, when I sorted the email alphabetically I could see that whoever posted that Pastebin listed most of the emails twice to make the list look longer than it actually was.Re: Update on Coinbase Data Security
#74You can add a soft rate limit with a captcha to make sure it's a human doing the requests rather than a spammer's script.
Re: Update on Coinbase Data Security
#75Earlier quoted context omitted.
A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)
What precautions have you taken against meatspace robbery? What's to stop 3 thugs with guns walking into your office(s) and cleaning out all the coins? Can you get insurance against this? Do you also have measures to prevent evil janitor attacks like hardware keyloggers being planted at 4:00am? Do you have screens facing an open window to watch from across the street? Can I rent beside your offices, drill holes throu…
Perhaps there are some bank executives for which this is true, but it is absolutely NOT the case for all banking executives. I work with some bank executives and they drive themselves to work in their own cars. The buildings DO have alarm systems and it is quite possible for the FBI to respond to physical threat incidents (because it is treated as a bank robbery) but otherwise there is little that is special in the way of physical security.
And for Coinbase, I believe the lack of special physical guards is appropriate. A high percentage ("up to 97%" according to https://coinbase.com/security ) of their coins are in cold storage and while I am not privy to the details of Coinbase's arrangements, keysharing and multiple physical storage locations that are off-premises are a reasonable precaution. They are vulnerable to hostage-taking or "3 thugs with guns" to the exact same extent (no greater) as any other company with a similar amount of protection.
I can't comment on protection against hardware keyloggers: it's a threat that they need to be prepared for. Cold storage is one major way of protecting against this threat, business insurance is another.
Re: Update on Coinbase Data Security
#76I always find my ‘skeptic’ meter ticks faster when I read of a data breach, and find a company: a) using language that is very specific when making a denial b) also introducing a new Director of Security in the same post
No new director was introduced; the Ryan McGeehan hire was in the news weeks ago.
Re: Update on Coinbase Data Security
#77No mention of the claimed IRS / Fed gag order, interesting. (although I realize its not their main focus right now)
Well they can't mention it if they have it, but they can mention if they don't. So this would be the only way Coinbase could communicate that they are under a gag order, barring a prior warrant canary. So it's probably prudent to act as if they have acknowledged the gag order until they deny it. Although it'd be really dumb if anyone was assuming the records were private. I guess they could say "We have implemented a…
Oh, and I'm under a federal gag order too... or at least there's no way to prove that I'm not.
Re: Update on Coinbase Data Security
#78They believe it's not a risk to their users (never minds those users who are now targeted via e-mail leak because they have BitCoins).
"You’ll also find many leading payment services allow user enumeration"
They also do pattern monitoring and rate limiting. And instead of saying 'but they do it!' they should be saying 'they do it too, but we think this is a valid privacy issue that we need to fix'.
This is more or less 'If you don't get privacy implications , we will bullshit you so you don't panic and go elsewhere with your money. Everything is fine!'
Re: Update on Coinbase Data Security
#79Re: Update on Coinbase Data Security
#80You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
You conveniently left out their next sentence "... many leading payment services allow user enumeration, including Paypal, Venmo, Square Cash, and many others..."