Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

101–110 of 135 posts

Re: Update on Coinbase Data Security

#101
post #28
post #6

Earlier quoted context omitted.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Three-finger click on OS X defines the word. Or right-click and Look up in Dictionary.

Control + Command + D also brings up the definition popover

Re: Update on Coinbase Data Security

#102
post #95
post #8

Earlier quoted context omitted.

We are pushing some changes to rate limiting - this wasn't clear in the original post and I just edited. Thanks for the heads up.

So why are you blowing this off and now all of a sudden writing rate limiting? The only reason he got 1000+ emails is because you guys messed up. Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'. Mistakes like this are signs of amateur hour.

Suppose they limit it to 100 emails before blocking your account. The guy can just sign up with 10 accounts. Or 5. This "attacker" would still post it and make a big fuss.

Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.

Re: Update on Coinbase Data Security

#104

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

Quite possible, but Coinbase really could have handled this better. They simply could have said, "You know what? While we don't agree with everything we're being accused of, we really value the community's trust and want you to know we're listening. First of all, we're really sorry to the folks who had their emails posted publicly. Secondly, we're doing XYZ to let you know we're on the case and re-evaluating our policies. Finally, we want to thank everyone who's reached out, you're helping to make Coinbase stronger."

Re: Update on Coinbase Data Security

#105
post #87

Earlier quoted context omitted.

They were given a bug report with three issues: 1) It's possible to determine if someone has a Coinbase account (no rate limit) 2) It's possible to find out someone's name if they have a Coinbase account (no rate limit) 3) Coinbase can be used to spam people through unsolicited messages (no rate limit). Their response basically equates to "so what, nothing's wrong". They ignored the initial reports and marked the bug…

The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.) Many people will take the feature of presenting the name, s…

> The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name.

Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers.

> Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.)

But that adds a barrier, and would give them time to notice. Your argument is the equivalent of "why have locks, all doors can be forced open". Just because security isn't perfect doesn't mean it's not worthwhile.

Re: Update on Coinbase Data Security

#106

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

Quite possible, but Coinbase really could have handled this better. They simply could have said, "You know what? While we don't agree with everything we're being accused of, we really value the community's trust and want you to know we're listening. First of all, we're really sorry to the folks who had their emails posted publicly. Secondly, we're doing XYZ to let you know we're on the case and re-evaluating our poli…

This is exactly what they wrote in the conclusions IMO. What don't you like about their version of expressing it?

Re: Update on Coinbase Data Security

#107

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

Quite possible, but Coinbase really could have handled this better. They simply could have said, "You know what? While we don't agree with everything we're being accused of, we really value the community's trust and want you to know we're listening. First of all, we're really sorry to the folks who had their emails posted publicly. Secondly, we're doing XYZ to let you know we're on the case and re-evaluating our poli…

I'm not sure that's the right approach either. They're not reevaluating their policies. They believe they did nothing wrong. Clearly some amateur hacker is the one exposing emails, probably from another source.

Re: Update on Coinbase Data Security

#108
post #95

Earlier quoted context omitted.

So why are you blowing this off and now all of a sudden writing rate limiting? The only reason he got 1000+ emails is because you guys messed up. Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'. Mistakes like this are signs of amateur hour.

Suppose they limit it to 100 emails before blocking your account. The guy can just sign up with 10 accounts. Or 5. This "attacker" would still post it and make a big fuss. Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.

In regards to rate limiting, it would be a much smaller number prior to block.

If it's IP based at let's say 10 over X attacker would have to lease 100 IP's.

In any case, rate limiting is the quickest mitigation prior to actual fix of the data leak in question.

Re: Update on Coinbase Data Security

#109
post #90

Earlier quoted context omitted.

So you are writing this off because 'only' 1153 emails were leaked? Then you are comparing security of virtual bank to something you did to Facebook back in the day. The thing is that, if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches, a serious attacker could (or already did) create his own list using let's say a combination of linked in + bit coin related doma…

>So you are writing this off because 'only' 1153 emails were leaked? His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153. >if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches You don't know that. He could have been trying for weeks. The percent…

How do you know it was an attempt of misleading and not a simple parsing or sorting/fitlering issue in bash or whatever he used to get emails?

Maybe the file was written to via different threads using cross linked dictionary?

Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out.

The bug that was filled was not even open for weeks. Again you are speculating without any facts.

http://blog.shubh.am/full-disclosure-coinbase-security/

You are comparing 'vulnerability' of a service meant for people to connect and find each other to a service that handles millions of dollars of users money.

Ridiculous.

Re: Update on Coinbase Data Security

#110
post #105

Earlier quoted context omitted.

The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.) Many people will take the feature of presenting the name, s…

> The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers. > Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do…

> Amazon won't tell you my name. Netflix won't tell you my name

If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it.

There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transaction with.

Post reply on HN