Live data from Hacker News

Coinbase design allows for mass, targeted phishing of its users

blog.shubh.am

71–75 of 75 posts

Re: Coinbase design allows for mass, targeted phishing of its users

#71
post #27

Divulging a name when presented with an email address is pretty bad and I'm not sure why it would be necessary. Just confirming that an email address is in the system is fairly minor.

Coinbase says the name is optional, so only people that chose to share their name are affected.

They didn't "choose to share their name". They just typed it into the form and there was no evidence that what is normally kept private was going to be divulged.

Re: Coinbase design allows for mass, targeted phishing of its users

#72
post #45

There's another bug when you can substitute coinbase's iframe with your own, when you use coinbase button. This iframe can ask for username / password, and there's no way for user to distinguish fake iframe from real. They also not into replying emails on their whitehat@ address.

+ there was another bug (or "feature") that allowed all access to all funds via API access key. Sure, the user needs to allow the permissions first, but the warning where disproportionate to the power it gave away. They've disabled this kind of access since though. http://www.theverge.com/2014/2/7/5386222/a-string-of-thefts-...

That was an old trick used by Liberty Reserve scammers too who would social engineer you to activate the API then clean out your wallets.

Re: Coinbase design allows for mass, targeted phishing of its users

#73
post #61

Earlier quoted context omitted.

Because Coinbase has moved the program out of email and into here: https://hackerone.com/coinbase

What they could do is turn it into an autoresponder at least with a link to that inside.

Yep, that's on the way!

Re: Coinbase design allows for mass, targeted phishing of its users

#74
post #69
post #59

Earlier quoted context omitted.

No, since there's no way to check iframe's domain I don't think it can be fixed for iframes . They should stop asking for user's password right there, because it makes people trust any iframe

Maybe they can force login via their main site first. Lousier user experience though.

Lousy user experience is not being able to verify what site I'm about to enter my payment credentials into.

Re: Coinbase design allows for mass, targeted phishing of its users

#75
post #74
post #69

Earlier quoted context omitted.

Maybe they can force login via their main site first. Lousier user experience though.

Lousy user experience is not being able to verify what site I'm about to enter my payment credentials into.

It would be a terrific experience if there was no reason to worry.
Post reply on HN