Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

131–135 of 135 posts

Re: Update on Coinbase Data Security

#131

Earlier quoted context omitted.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

Maybe in the US they don't, but in Canada you can. I'm quite sure in most of Europe & Australia you can as well.

You can't in Australia

Source: I live in Australia

Re: Update on Coinbase Data Security

#132
post #85

Earlier quoted context omitted.

There's only one explanation for why you can't get service for problems unless you're featured on reddit, why they don't care about security, and why they're flagrantly dishonest in their comparisons: because they don't respect us, at all.

Or they're a tiny company trying to push in all areas at the same time, and they have to prioritize, and sometimes things they'd want to do fall through the cracks or they just haven't had a chance to do them yet. If you've ever been at a small company, you know that this is the much more likely scenario. Requiring them to have already implemented all of the security measures of Paypal, which has been around for more…

Being small does not explain total customer service failure, the lack of daily reconciliation reports (which would spot things like $x0,000 deposits that weren't tied to a purchase), or the dishonesty about the ability to enumerate emails on other payment platforms without getting banned.

That said, this is HN, so I'm already banned for saying something very slightly critical of a YC company, even though that company is fucking up hard.

Re: Update on Coinbase Data Security

#133
post #77

Earlier quoted context omitted.

Yes. And while we're at it, I wanted to point out that cbcbcb (who posted the initial leak) is ALSO under a federal gag order. He/she either won't deny it (because, obviously, they can't) or WILL lie and deny it (forced to lie by the gag order). Oh, and I'm under a federal gag order too... or at least there's no way to prove that I'm not.

Has it been shown that the USG can order an entity to lie?

There has been speculation among legal scholars that the legal threshold for ordering someone to lie might be greater than the legal threshold for ordering someone to keep silent. This has not been tested in court (at least, not in open court) so no one knows for sure. If I received a national security letter ordering me to lie, I would have to think VERY carefully before deciding to violate it and become a test case.

Re: Update on Coinbase Data Security

#134
post #75

Earlier quoted context omitted.

> meanwhile bank execs are dropped off at work by private guards specializing in counter-kidnapping operations Perhaps there are some bank executives for which this is true, but it is absolutely NOT the case for all banking executives. I work with some bank executives and they drive themselves to work in their own cars. The buildings DO have alarm systems and it is quite possible for the FBI to respond to physical th…

Any other company doesn't need to worry since robbing their head office and demanding online bank transfers is a waste of time. A cryptocoin fixed rate exchange with millions in storage you can instantly transfer is a different story. It's like Ft. Knox being located in a regular office building with gold piled on the desks. Bank vaults have physical security so why don't Bitcoin based businesses. I did read through…

> They would need access to the cold wallet on a regular basis if 97% of funds are truly in there.

Not true. First of all, that would only be true if their net daily turnover were more than 3% of their total amount stored -- which it may not be. Even then, I would expect graduated levels of cold wallets: imagine one with another 2% that is down the street in a bank safe deposit box, 5 wallets with 50% of the deposits stored in a way that can only be accessed with cooperation of 4 people in different parts of the country ... that sort of thing.

I am, of course, just speculating: I don't know how Coinbase runs their system, I just know that they seem competent and that this is how I would run such a thing.

Re: Update on Coinbase Data Security

#135

While not ideal, I think this is being blown out of proportion by someone that doesn't like Coinbase. For starters, of the 2042 "leaked" emails, 1153 are unique. That means the person that posted it was trying to pad their results, which combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out. Enumeration isn't a fantastic idea, but given its ubi…

> That means the person that posted it was trying to pad their results Not necessarily. The duplicates are in exact order(quick check using sublime). Could have just been a double paste, happens very often. The fear mongering (FBI et al) definitely seems unfounded. > illustrates that someone is mad at Coinbase and is lashing out That's an ad hominem attack. > I don't think it's worthy of all of this negative attentio…

>> illustrates that someone is mad at Coinbase and is lashing out

>That's an ad hominem attack.

No it isn't. I honestly wish that people would stop erroneously calling out logical fallacies. An ad hominem attack is refuting someone's argument by attacking their character in a way that has nothing to do with the discussion. For example, this is an ad hominem attack:

Obama: ObamaCare has insured 7.1 million people through the exchanges.

Sally: Oh sure, but what difference does that make - you're a muslim and want this country to fail!

That is an ad hominem. Because Obama being (or not being) a muslim is irrelevant to the discussion and is only used to impugn the character of Obama.

What is not an ad hominem attack is evaluating evidence of someone padding numbers to make Coinbase look bad and then determining that they must be biased against Coinbase. If you think evaluating evidence and coming to negative conclusions about someone is an ad hominem attack, then you are seriously mistaken.

Post reply on HN