Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

91–100 of 135 posts

Re: Update on Coinbase Data Security

#91
post #14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

Why wasn't any of that information in the earlier statements? When given a list that contains demonstrable flaws "we see your list and don't think it's a problem (thus by implication are not doing anything about it)" does not induce confidence, it sounds like hubris.

Simply writing that the rate limiting wasn't working correctly and you were fixing would have made all the difference in the world to me.

Re: Update on Coinbase Data Security

#92
post #60
post #28

Earlier quoted context omitted.

Three-finger click on OS X defines the word. Or right-click and Look up in Dictionary.

Indeed, and a great trick too — but that appears to be a great but non-default option, only working within Apple software (namely Safari browser when surfing HN) and uses the System language (not English for me). I personally prefer Right click “Search with Google…” in Chrome: it has the upside of coming up with a definition when the word is actually rare -- so it prevents me from defining an word I didn't know simpl…

It works in any software in OS X using standard text controls. It's insanely handy.

The few programs I use that don't support it actually drive me nuts because I've become so used to it.

The system language thing is a little annoying. It would be fantastic to be able to look up the random Spanish or Japanese word, but I understand the limitation.

Re: Update on Coinbase Data Security

#93
post #70

>there has been no data breach of names or emails at Coinbase I have a Pastebin URL with 200 email addresses to prove the contrary. Why lie in PR?

You have to have the email addresses before you can query Coinbase with them. The addresses didn't originate with Coinbase, the attacker already had them.

Were you certain they were Coinbase users? Did you have the first and last names?

Re: Update on Coinbase Data Security

#94
post #91
post #14

Earlier quoted context omitted.

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us. Hope this helps clarify (edited for formatting)

Why wasn't any of that information in the earlier statements? When given a list that contains demonstrable flaws "we see your list and don't think it's a problem (thus by implication are not doing anything about it)" does not induce confidence, it sounds like hubris. Simply writing that the rate limiting wasn't working correctly and you were fixing would have made all the difference in the world to me.

Because then it will be bad PR.

Now they can play it off so people who don't know any better won't move to another service.

Re: Update on Coinbase Data Security

#95
post #8

Rate limiting Do we have to spell it out to them?

We are pushing some changes to rate limiting - this wasn't clear in the original post and I just edited. Thanks for the heads up.

So why are you blowing this off and now all of a sudden writing rate limiting?

The only reason he got 1000+ emails is because you guys messed up.

Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'.

Mistakes like this are signs of amateur hour.

Re: Update on Coinbase Data Security

#96
post #66
post #49

If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

If you read the post even a little bit carefully, they refute the idea that this was a harvesting of their database. One compelling bit of evidence they present is that the list is tiny, and their customer list is very large. It's not just that this isn't a "large scale" leak; it's that they say it's not a leak at all ; that this data was made available through some other combination of services that exposed it, not…

Coinbase's tone at https://hackerone.com/reports/5200 convinces me that they just don't care about user account enumeration. Combined with the blog post, my sense is that Coinbase does not deny that systematic enumeration is possible; rather, they deny that we should worry about it. ("it's not a bug, it's a feature")

Re: Update on Coinbase Data Security

#97
post #77

Earlier quoted context omitted.

Well they can't mention it if they have it, but they can mention if they don't. So this would be the only way Coinbase could communicate that they are under a gag order, barring a prior warrant canary. So it's probably prudent to act as if they have acknowledged the gag order until they deny it. Although it'd be really dumb if anyone was assuming the records were private. I guess they could say "We have implemented a…

Yes. And while we're at it, I wanted to point out that cbcbcb (who posted the initial leak) is ALSO under a federal gag order. He/she either won't deny it (because, obviously, they can't) or WILL lie and deny it (forced to lie by the gag order). Oh, and I'm under a federal gag order too... or at least there's no way to prove that I'm not.

Has it been shown that the USG can order an entity to lie?

Re: Update on Coinbase Data Security

#98
post #90

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

So you are writing this off because 'only' 1153 emails were leaked? Then you are comparing security of virtual bank to something you did to Facebook back in the day. The thing is that, if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches, a serious attacker could (or already did) create his own list using let's say a combination of linked in + bit coin related doma…

>So you are writing this off because 'only' 1153 emails were leaked?

His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153.

>if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches

You don't know that. He could have been trying for weeks. The percentage of the internet that has Coinbase accounts is minuscule, and this attack requires one to correctly guess that a particular email is already attached to a Coinbase account. The fact that he falsely doubled the size of his list is a testament to this.

>Then you are comparing security of virtual bank to something you did to Facebook back in the day.

This wasn't that long ago, but my point was that this "vulnerability" is minor compared to other sites, yet the backlash against Coinbase seems to be far greater.

Re: Update on Coinbase Data Security

#99
post #87
post #39

Earlier quoted context omitted.

For those of us getting caught up on these events - what evidence are you referring to? So far I've seen : 1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders 2) Homakov's email to whitehat@ concerning a potential iframe vuln What am I missing?

They were given a bug report with three issues: 1) It's possible to determine if someone has a Coinbase account (no rate limit) 2) It's possible to find out someone's name if they have a Coinbase account (no rate limit) 3) Coinbase can be used to spam people through unsolicited messages (no rate limit). Their response basically equates to "so what, nothing's wrong". They ignored the initial reports and marked the bug…

The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name.

Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.)

Many people will take the feature of presenting the name, so you have another layer of comfort while making the transaction (knowing it went to the right place, that you didn't introduce a typo) to be a feature. And those that don't want it don't have to provide their names.

Re: Update on Coinbase Data Security

#100
post #64
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

It is not my experience that financial services companies are substantially better than startups on cosmetic security issues like username enumeration.

Some financial services are even worse. One of the largest banks/brokerage sites truncates passwords at 8 characters without notifying the user. It is possible for the user to save their password as "password104n35dsu348a21p9sdj28x". They might feel pretty safe with the length, (pseudo) randomness, and complexity of that password, but someone would be able to log into their account by simply entering "password".

However, the big differentiating factor between startups and financial service companies is the faith in them "making it right" when something does go wrong. At this point, we have little reason to believe that one huge security issue won't simply kill a startup like Coinbase and leave all of its account holders out in the cold. It seems pretty safe to say that wouldn't happen with any major bank in the US.

Post reply on HN