Update on Coinbase Data Security
81–90 of 135 posts
Re: Update on Coinbase Data Security
#82I always find my ‘skeptic’ meter ticks faster when I read of a data breach, and find a company: a) using language that is very specific when making a denial b) also introducing a new Director of Security in the same post
Re: Update on Coinbase Data Security
#83Earlier quoted context omitted.
What precautions have you taken against meatspace robbery? What's to stop 3 thugs with guns walking into your office(s) and cleaning out all the coins? Can you get insurance against this? Do you also have measures to prevent evil janitor attacks like hardware keyloggers being planted at 4:00am? Do you have screens facing an open window to watch from across the street? Can I rent beside your offices, drill holes throu…
> meanwhile bank execs are dropped off at work by private guards specializing in counter-kidnapping operations Perhaps there are some bank executives for which this is true, but it is absolutely NOT the case for all banking executives. I work with some bank executives and they drive themselves to work in their own cars. The buildings DO have alarm systems and it is quite possible for the FBI to respond to physical th…
I did read through their security about the backups being spread around different locations, but those are backups. They would need access to the cold wallet on a regular basis if 97% of funds are truly in there. Unlikely to happen but then again police here didn't expect criminals would remove huge concrete barriers with a stolen tractor, ram a shopping mall entrance, drive through the mall and ram a gated jewelry store but they did.
Re: Update on Coinbase Data Security
#84If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.
they say the list is less than 0.5% of their total user base. Not sure if you can call this "large-scale".
Re: Update on Coinbase Data Security
#85Earlier quoted context omitted.
Because I was talking about banks & processors, not payment services. Paypal will cut you off hard if you attempt to bulk enumerate users/businesses by e-mail address, so this is even more disingenuous on the part of Coinbase.
There's only one explanation for why you can't get service for problems unless you're featured on reddit, why they don't care about security, and why they're flagrantly dishonest in their comparisons: because they don't respect us, at all.
If you don't trust them to hold on to your coins, use them purely an exchange and then pull them off onto an offline wallet.
Re: Update on Coinbase Data Security
#86Re: Update on Coinbase Data Security
#87Earlier quoted context omitted.
'We didn't do anything wrong, this isn't a bug, nothing to see here.' despite obvious evidence to the contrary. Very confidence inducing.
For those of us getting caught up on these events - what evidence are you referring to? So far I've seen : 1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders 2) Homakov's email to whitehat@ concerning a potential iframe vuln What am I missing?
1) It's possible to determine if someone has a Coinbase account (no rate limit)
2) It's possible to find out someone's name if they have a Coinbase account (no rate limit)
3) Coinbase can be used to spam people through unsolicited messages (no rate limit).
Their response basically equates to "so what, nothing's wrong". They ignored the initial reports and marked the bug as won't fix.
Someone used this vulnerability to pull a bunch of example addresses and their response is "so what, nothing's wrong, probably wasn't us".
But these are three serious issues.
1) Why should anyone be able to figure this out without being a registered application? This is especially true given #3. And the lack of rate limiting is just irresponsible.
2) Why should anyone be able to ask Coinbase what my name is? Even if they allowed that, why can you do it without being a registered user of their API? Again, the lack of rate limiting is also irresponsible.
3) I understand it's purposeful that they'll treat anyone as having an account for the purposes of on boarding, that make sense. But the ability to send emails to anyone on the internet without risking my reputation is asking for trouble. Again, this should be heavily rate limited unless you've registered with them. Anyone can sign up for an Amazon SES account, but you have to go through a few hoops before you can start sending out 500 messages a second.
These statements read like Baghdad Bob to me. We don't agree, nothing is wrong, go about your business as if nothing had happened.
If their initial response was "that's all correct, we're looking into rate limiting and maybe requiring you to register to make API calls" that would have been the end of it.
If I want to send money to someone, I should call Coinbase and they should send the request. The response to me should be "sent" or "error". Imagine if whenever I paid a bill with my credit card the return was not just "success" or "failure" but "success", "current balance", and "mother's maiden name". Disclosing that extra information is totally unnecessary.
Re: Update on Coinbase Data Security
#88You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
It is not my experience that financial services companies are substantially better than startups on cosmetic security issues like username enumeration.
Re: Update on Coinbase Data Security
#89Earlier quoted context omitted.
What precautions have you taken against meatspace robbery? What's to stop 3 thugs with guns walking into your office(s) and cleaning out all the coins? Can you get insurance against this? Do you also have measures to prevent evil janitor attacks like hardware keyloggers being planted at 4:00am? Do you have screens facing an open window to watch from across the street? Can I rent beside your offices, drill holes throu…
> meanwhile bank execs are dropped off at work by private guards specializing in counter-kidnapping operations Perhaps there are some bank executives for which this is true, but it is absolutely NOT the case for all banking executives. I work with some bank executives and they drive themselves to work in their own cars. The buildings DO have alarm systems and it is quite possible for the FBI to respond to physical th…
An armed guard, 24/7 security cameras (obvious and hidden) actively being watched by a human being, established passphrases for when the security service calls to check in, etc.
They are at as least as much risk as a physical bank branch, it's a bit of denial on their part if they aren't treating it that way.
Re: Update on Coinbase Data Security
#90While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…
Then you are comparing security of virtual bank to something you did to Facebook back in the day.
The thing is that, if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches, a serious attacker could (or already did) create his own list using let's say a combination of linked in + bit coin related domains to:
1. Harvest valid emails of people employed in a bit coin sector.
2. Match them against coinbase.
3. Start phishing.
Really simple.