Earlier quoted context omitted.
copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)
Three-finger click on OS X defines the word. Or right-click and Look up in Dictionary.
Update on Coinbase Data Security
101–110 of 135 posts
Re: Update on Coinbase Data Security
#102Earlier quoted context omitted.
We are pushing some changes to rate limiting - this wasn't clear in the original post and I just edited. Thanks for the heads up.
So why are you blowing this off and now all of a sudden writing rate limiting? The only reason he got 1000+ emails is because you guys messed up. Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'. Mistakes like this are signs of amateur hour.
Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.
Re: Update on Coinbase Data Security
#103Re: Update on Coinbase Data Security
#104While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…
Re: Update on Coinbase Data Security
#105Earlier quoted context omitted.
They were given a bug report with three issues: 1) It's possible to determine if someone has a Coinbase account (no rate limit) 2) It's possible to find out someone's name if they have a Coinbase account (no rate limit) 3) Coinbase can be used to spam people through unsolicited messages (no rate limit). Their response basically equates to "so what, nothing's wrong". They ignored the initial reports and marked the bug…
The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.) Many people will take the feature of presenting the name, s…
Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers.
> Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.)
But that adds a barrier, and would give them time to notice. Your argument is the equivalent of "why have locks, all doors can be forced open". Just because security isn't perfect doesn't mean it's not worthwhile.
Re: Update on Coinbase Data Security
#106While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…
Quite possible, but Coinbase really could have handled this better. They simply could have said, "You know what? While we don't agree with everything we're being accused of, we really value the community's trust and want you to know we're listening. First of all, we're really sorry to the folks who had their emails posted publicly. Secondly, we're doing XYZ to let you know we're on the case and re-evaluating our poli…
Re: Update on Coinbase Data Security
#107While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…
Quite possible, but Coinbase really could have handled this better. They simply could have said, "You know what? While we don't agree with everything we're being accused of, we really value the community's trust and want you to know we're listening. First of all, we're really sorry to the folks who had their emails posted publicly. Secondly, we're doing XYZ to let you know we're on the case and re-evaluating our poli…
Re: Update on Coinbase Data Security
#108Earlier quoted context omitted.
So why are you blowing this off and now all of a sudden writing rate limiting? The only reason he got 1000+ emails is because you guys messed up. Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'. Mistakes like this are signs of amateur hour.
Suppose they limit it to 100 emails before blocking your account. The guy can just sign up with 10 accounts. Or 5. This "attacker" would still post it and make a big fuss. Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.
If it's IP based at let's say 10 over X attacker would have to lease 100 IP's.
In any case, rate limiting is the quickest mitigation prior to actual fix of the data leak in question.
Re: Update on Coinbase Data Security
#109Earlier quoted context omitted.
So you are writing this off because 'only' 1153 emails were leaked? Then you are comparing security of virtual bank to something you did to Facebook back in the day. The thing is that, if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches, a serious attacker could (or already did) create his own list using let's say a combination of linked in + bit coin related doma…
>So you are writing this off because 'only' 1153 emails were leaked? His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153. >if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches You don't know that. He could have been trying for weeks. The percent…
Maybe the file was written to via different threads using cross linked dictionary?
Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out.
The bug that was filled was not even open for weeks. Again you are speculating without any facts.
http://blog.shubh.am/full-disclosure-coinbase-security/
You are comparing 'vulnerability' of a service meant for people to connect and find each other to a service that handles millions of dollars of users money.
Ridiculous.
Re: Update on Coinbase Data Security
#110Earlier quoted context omitted.
The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.) Many people will take the feature of presenting the name, s…
> The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers. > Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do…
If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it.
There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transaction with.