Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

121–130 of 135 posts

Re: Update on Coinbase Data Security

#121

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

> That means the person that posted it was trying to pad their results

Not necessarily. The duplicates are in exact order(quick check using sublime). Could have just been a double paste, happens very often.

The fear mongering (FBI et al) definitely seems unfounded.

> illustrates that someone is mad at Coinbase and is lashing out

That's an ad hominem attack.

> I don't think it's worthy of all of this negative attention directed specifically at Coinbase either

Agreed Coinbase is the target of a lot of negative attention. That does not discount that enumeration deserves any less attention, it's unnecessary and poses more risks than benefits (again I don't know of a single benefit when requesting funds - when sending funds it is understandable but still problematic).

> We are acting as pawns in someone's revenge scheme against Coinbase

You're giving people too little credit. Coinbase is bad at communicating (timing and message), bad communication pisses people of. They are also in a business that gets more scrutiny than other payment processors.

Re: Update on Coinbase Data Security

#122
post #115

Earlier quoted context omitted.

Amazon won't tell you my name until I make a transaction with you . If I add your item to my cart and never check out, they won't tell you anything about me. That doesn't seem to be the case with Coinbase, they seem to give you the information when you propose a transaction.

Yes, with these newly moved goalposts, I agree, and I mentioned it earlier today: Coinbase is giving your ID not just to people you've interacted with (which makes sense) but to people who have expressed the vaguest desire to interact with you (might might not make sense). But in the comment I was replying to was pointing out that Netflix never gives your ID to anybody, which is not a fair comparison because Netflix…

That's not moving goalposts. Amazon does not give out my information to unregistered 3rd parties who I haven't made a transaction with. Seems Coinbase does.

I chose Netflix simply because they were a large internet company. I think the idea that Coinbase is involved in transactions is a red herring here since they're giving the information out before the transactions are agreed upon by both parties.

If I proposed a Coinbase transaction with someone, I would fully expect that the other party would be told my name and possibly even my email.

Re: Update on Coinbase Data Security

#123
post #96
post #66

Earlier quoted context omitted.

If you read the post even a little bit carefully, they refute the idea that this was a harvesting of their database. One compelling bit of evidence they present is that the list is tiny, and their customer list is very large. It's not just that this isn't a "large scale" leak; it's that they say it's not a leak at all ; that this data was made available through some other combination of services that exposed it, not…

Coinbase's tone at https://hackerone.com/reports/5200 convinces me that they just don't care about user account enumeration. Combined with the blog post, my sense is that Coinbase does not deny that systematic enumeration is possible; rather, they deny that we should worry about it. ("it's not a bug, it's a feature")

I don't know if they do or don't, but I wouldn't be surprised either way, because I sure don't care about user account enumeration. We doc it, but I'm always embarrassed when we do.

Re: Update on Coinbase Data Security

#124

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

> That means the person that posted it was trying to pad their results Not necessarily. The duplicates are in exact order(quick check using sublime). Could have just been a double paste, happens very often. The fear mongering (FBI et al) definitely seems unfounded. > illustrates that someone is mad at Coinbase and is lashing out That's an ad hominem attack. > I don't think it's worthy of all of this negative attentio…

These are serious accusations against Coinbase. There is absolutely no excuse for an artificial 2x inflation of numbers, especially for something that's supposed to be "partial"

Re: Update on Coinbase Data Security

#125
post #65

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

> For starters, of the 2042 "leaked" emails, 1153 are unique. Nice observation. I hadn't noticed it at a glance. > combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. I agree. Those are bold accusations, and bold accusations require at least some proof.

> bold accusations require at least /some/ proof.

Can you expand? I thought all accusations needed strong evidence.

Re: Update on Coinbase Data Security

#126
post #125
post #65

Earlier quoted context omitted.

> For starters, of the 2042 "leaked" emails, 1153 are unique. Nice observation. I hadn't noticed it at a glance. > combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. I agree. Those are bold accusations, and bold accusations require at least some proof.

> bold accusations require at least /some/ proof. Can you expand? I thought all accusations needed strong evidence.

I was being hyperbolical.

Re: Update on Coinbase Data Security

#127
I was phished for coinbase just recently with an email telling me "You just received 0.08525920 BTC" and just "Click here to sign in and view this transaction" and I stupidly I did click on the link and did try to log in. The login failed (as it would with a trojan and the coinbase 2 factor authentication I have enabled). But even so, the phishing site was able to attach 3 Android apps to my account with full access. I deleted the apps and notified coinbase, but they were totally less than helpful.

Re: Update on Coinbase Data Security

#128
post #119
post #109

Earlier quoted context omitted.

How do you know it was an attempt of misleading and not a simple parsing or sorting/fitlering issue in bash or whatever he used to get emails? Maybe the file was written to via different threads using cross linked dictionary? Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out. The bug that was filled was not even open for weeks. Again you are specu…

You're the one being ridiculous. - There was no email leak from Coinbase. The source of the email list used against the API is unknown at this time. - Someone who's savvy enough to call an an API in a multi-threaded fashion but doesn't know how to: cat email_list.txt | sort | uniq ? meh, unlikely. - User enumeration hardly equals a vulnerability and the name you put on the account doesn't have to be your real name. I…

They leaked accounts that are legit, who cares about the source when Coinbase confirmed that this instance with some random unknown list 'only' impacted 1000+ users.

Sure, but they could also not care if there are duplicates. You don't need to polish your list output for a proof of concept code, whatever he needed to prove was proven.

It's not a vulnerability, it's data leakage. Sure you put a wrong name in, most people did not.

And it's not the name that's a concern it's leakage of email addresses that would be prime target for savvy hackers who want bitcoins.

If you could run random addresses against an API offered by a vendor that sells safes for high value valuables and get a match which houses have those safes you become a target.

Sure most people won't try to break in, but those are are in business of doing so will try.

Re: Update on Coinbase Data Security

#129
post #53
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

"It’s clear there was no data breach because no other user information is provided." That strikes me as an assumption. There's no way for them to know that there was no breach based off of the fact that no other information was provided. There are other ways to know that you were not breached, this one comes across as a very weak / naive reason.

Even if certain users were in fact somehow phished or deceived by this, it would be a stretch to say that is a "breach".

Regardless, I do think Coinbase should try to prevent user enumeration.

Re: Update on Coinbase Data Security

#130

I was phished for coinbase just recently with an email telling me "You just received 0.08525920 BTC" and just "Click here to sign in and view this transaction" and I stupidly I did click on the link and did try to log in. The login failed (as it would with a trojan and the coinbase 2 factor authentication I have enabled). But even so, the phishing site was able to attach 3 Android apps to my account with full access.…

People should upvote this much more. This shows that the reported exposure has resulted in at least one successful phishing.

The fact that the 2 factor auth can apparently be bypassed by attaching apps is another security vulnerability entirely. If that is what you are claiming is the case, then they should be immediately fixing this as soon as you reported it to them.

Post reply on HN