Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

111–120 of 135 posts

Re: Update on Coinbase Data Security

#111
post #109

Earlier quoted context omitted.

>So you are writing this off because 'only' 1153 emails were leaked? His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153. >if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches You don't know that. He could have been trying for weeks. The percent…

How do you know it was an attempt of misleading and not a simple parsing or sorting/fitlering issue in bash or whatever he used to get emails? Maybe the file was written to via different threads using cross linked dictionary? Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out. The bug that was filled was not even open for weeks. Again you are specu…

>You are comparing 'vulnerability' of a service meant for people to connect and find each other to a service that handles millions of dollars of users money. Ridiculous.

So you are saying that this somehow endangered customer funds?

Re: Update on Coinbase Data Security

#112
post #86

There was no mention of the IRS and FBI gag orders/data transfer in this post.

Because those were bogus.

In retrospect, it should have been a huge warning sign that the entire thing was bogus. At worst (for Coinbase), they have someone reporting a legit security issue with a bunch of jokes at the top.

Re: Update on Coinbase Data Security

#113
post #86

There was no mention of the IRS and FBI gag orders/data transfer in this post.

I filed a Freedom of Information Act request to the FBI about Coinbase, and they replied that they have no documents. https://www.muckrock.com/foi/united-states-of-america-10/coi... Of course, the FBI is explicitly allow to lie in response to FOIA requests if it will protect an ongoing investigation.

However, I was also told at a party by a Coinbase employee that this is not true (which is why I filed the request to begin with.)

I am certain that they have a relationship.

Re: Update on Coinbase Data Security

#114
I also think this whole thing is overblown but I hope it will help to further humble Coinbase in realizing that they really need to focus more efforts on squashing things like this before they become a problem. Coinbase has a large responsibility in whether or not Bitcoin is to become "accepted" in the USA and several small events like these left unsettled or left to fester could prove catastrophic(IMO).

I don't believe Coinbase should consider this a real "security threat". I believe that this is a negative side-effect of what may be a feature. It is certainly something that needs improvement, as I'm sure all of the people whose email has been leaked will tell you...

I'm not sure if Coinbase has an engineering blog or a similar outlet where they can speak to more developers directly but if they do not have one already, this may be the time to start. This could've been squashed entirely within a small development community but when left unsettled for so long, it is things like this that the news will latch onto and run with We all know how blown out of proportion things get when that happens.

Anyway, long story short... I hope Coinbase improves. As much as I hate to say that a tech company needs more representatie

Re: Update on Coinbase Data Security

#115
post #105

Earlier quoted context omitted.

> The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers. > Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do…

> Amazon won't tell you my name. Netflix won't tell you my name If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it. There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transact…

Amazon won't tell you my name until I make a transaction with you. If I add your item to my cart and never check out, they won't tell you anything about me.

That doesn't seem to be the case with Coinbase, they seem to give you the information when you propose a transaction.

Re: Update on Coinbase Data Security

#116
post #105

Earlier quoted context omitted.

> The name is optional, and you can supply it to make the experience nicer. If you don't plan on using Coinbase this way, don't supply a name. Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers. > Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do…

> Amazon won't tell you my name. Netflix won't tell you my name If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it. There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transact…

> However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transaction with

Why is this? They are not receiving money , they are sending money. The recipient needs to know the sender but why does the sender need to know that the recipient is a registered coinbase user or what their firstname and lastname is. Why does the response json of the request_money api need to return the user's name and couldn't the email and the transaction history page be the same when you send money to a registered or non-registered email until the recipient is in some sort of address book of the sender (perhaps after a valid transaction has happened between them). I have used chase and paypal and in both cases either I have to add the recipient to the address book and fill out the email address and first and last names or just use the email address.

Fortunately or unfortunately when you play in the financial services, you are held to a higher security standard. I really like coinbase, I hope they fix this simple problem and move on instead of denying its a problem.

Re: Update on Coinbase Data Security

#117
post #84
post #62

Earlier quoted context omitted.

they say the list is less than 0.5% of their total user base. Not sure if you can call this "large-scale".

I agree that 1000+ people may not be "large-scale" depending on how we define it, but I do see it as a proof of concept that Coinbase permits large-scale user enumeration. (Not that it has necessarily happened yet)

Yea ok, I got your point :)

Now we just need to make sure the data came from coinbase directly, which they refute. They say data comes from other services - mostly bitcoin related ones.

Re: Update on Coinbase Data Security

#118
post #115

Earlier quoted context omitted.

> Amazon won't tell you my name. Netflix won't tell you my name If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it. There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transact…

Amazon won't tell you my name until I make a transaction with you . If I add your item to my cart and never check out, they won't tell you anything about me. That doesn't seem to be the case with Coinbase, they seem to give you the information when you propose a transaction.

Yes, with these newly moved goalposts, I agree, and I mentioned it earlier today: Coinbase is giving your ID not just to people you've interacted with (which makes sense) but to people who have expressed the vaguest desire to interact with you (might might not make sense).

But in the comment I was replying to was pointing out that Netflix never gives your ID to anybody, which is not a fair comparison because Netflix is in an entirely different business. Netflix customers never interact with each other. Coinbase users do interact, and identity is usually essential for interaction.

Re: Update on Coinbase Data Security

#119
post #109

Earlier quoted context omitted.

>So you are writing this off because 'only' 1153 emails were leaked? His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153. >if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches You don't know that. He could have been trying for weeks. The percent…

How do you know it was an attempt of misleading and not a simple parsing or sorting/fitlering issue in bash or whatever he used to get emails? Maybe the file was written to via different threads using cross linked dictionary? Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out. The bug that was filled was not even open for weeks. Again you are specu…

You're the one being ridiculous.

- There was no email leak from Coinbase. The source of the email list used against the API is unknown at this time.

- Someone who's savvy enough to call an an API in a multi-threaded fashion but doesn't know how to: cat email_list.txt | sort | uniq ? meh, unlikely.

- User enumeration hardly equals a vulnerability and the name you put on the account doesn't have to be your real name. I have "SMTDDR" on it. All you'd get is "SMTDDR".

Really, this is some kind of political-mud-slinging at Coinbase. Wake me up when you can pull my banking info or transfer my coins out of my account.

Re: Update on Coinbase Data Security

#120
post #66
post #49

If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security. This is a service that stores digital cash . It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

If you read the post even a little bit carefully, they refute the idea that this was a harvesting of their database. One compelling bit of evidence they present is that the list is tiny, and their customer list is very large. It's not just that this isn't a "large scale" leak; it's that they say it's not a leak at all ; that this data was made available through some other combination of services that exposed it, not…

this data was made available through some other combination of services that exposed it, not Coinbase

That assumes the acknowledgement of whether a given email address is a member or not is not data in itself. That is arguable. For example, I know that in healthcare, merely confirming whether someone is a patient of yours is a violation.

But I agree with the larger point that the original disclosure is overblown.

Post reply on HN