Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…
Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.
Coinbase user emails and full names leaked
281–290 of 294 posts
Re: Coinbase user emails and full names leaked
#282Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…
There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.
"This is the bullshit excuse they are trying to use to make it SEEM like its not a vulnerability."
Coinbase is deliberately misleading their users regarding privacy if they do not fix this issue!
Re: Coinbase user emails and full names leaked
#283Earlier quoted context omitted.
I work on dating sites, some of them a bit risqué. On the password reset form, there's a big difference between saying "That email does not exist in our system"/"Emailed password reset instructions" vs "If that account is registered, we will email you instructions".
How do you handle users attempting to register a new account with an email address that already exists? If you say, "we don't allow two accounts with the same email address", you have the same issue as coinbase.
Re: Coinbase user emails and full names leaked
#284Earlier quoted context omitted.
What other information is it leaking?
From what I gather, first name and last name. Stopping email address validation is, I think, impossible for a company like Coinbase, but revealing the name doesn't have to happen. On the other hand, providing the first and last name could be very valuable to the users, though. If I send coins to bob@example.com, I'd like to see the real name behind that address. On the other other hand, if anyone can make any first a…
(1) is opt-in on the recipient's side and fails with something like "that recipient email address doesn't have an account, the name doesn't match, or they haven't decided to allow name verification"
AND
(2) is only available on payments above your highest guess at the expected value of matching an account-email-name triple for spearphishing, and the error messages (and timings) are identical if the name doesn't match or the given email address doesn't have an account.
I imagine there are few profitable attacks where an answer "yes, email_address with name has a Coinbase account" costs a minimum of 100 USD to an attacker and getting an answer "Either email_address doesn't have an account, that name doesn't match our records, or they've chosen not to share their name" costs 0 USD. However, I'd have to think a bit more about that 100 USD minimum.
Re: Coinbase user emails and full names leaked
#285Changing contact info now to: line 34 of the coinbase leak-list on pastebin.
Re: Coinbase user emails and full names leaked
#286Earlier quoted context omitted.
How do you handle users attempting to register a new account with an email address that already exists? If you say, "we don't allow two accounts with the same email address", you have the same issue as coinbase.
For the case of people attempting to sign up a second time with the same email address, don't change anything shown from the webpage. Instead of sending a verification email, send an email informing them that someone is trying to sign up again with the same email address, and include an expiring password reset link in that email. If you see too many users forgetting that they've already signed up, and getting frustra…
I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.
Re: Coinbase user emails and full names leaked
#287Earlier quoted context omitted.
What does that have to do with what I said? I think the manner in which you made your point has too high a chance of being misinterpreted to be acceptable here, which is probably why it was being downvoted.
I get your point, yet somebody misinterpreting a joke should have no impact on the company... Unless the company actually had inadequate reserves to meet customer withdrawals, thus leaving the solvency of the company at risk of a good old-fashioned fractional reserve style bank-run...
Re: Coinbase user emails and full names leaked
#288Earlier quoted context omitted.
For the case of people attempting to sign up a second time with the same email address, don't change anything shown from the webpage. Instead of sending a verification email, send an email informing them that someone is trying to sign up again with the same email address, and include an expiring password reset link in that email. If you see too many users forgetting that they've already signed up, and getting frustra…
So you'll allow a user to go all the way through the process of registration, create a new password, get temporary access to your site... and then what... not save that password? So a re-login attempt won't work? I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.
> I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.
The workflow diverges at the email verification step, before you grant any access to the site. Existing users get an email informing them that someone has tried to sign up a second time using their email address while new users get the standard email verification email.
I highly recommend not allowing account creation before email address verification. I have a difficult to spell last name, so I have one email address that contains my initials and a common word instead of my last name. You'd be surprised the number of people who don't know their own email address and the number of sites that allow people to sign up (and apparently transact significantly) without verifying email addresses. Off the top of my head, if I wanted to, I could steal one person's tax accounting account (I got confirmation that they filed their state taxes this year, and later confirmation their state accepted their filing), another person's car rental account, and a third person's business's trash service account. From time to time the one person tries to reset their car rental account password. I imagine I could reset the passwords for all of these accounts (and others) and get the last 4 digits of their credit card numbers and other personal information and use that as a starting point for gaining access to other accounts they own. In the case of the tax account, I could probably re-download the tax paperwork and get their SSN. Neither the tax accounting company nor the car rental agency replied when I informed them that accounts were set up with the wrong email addresses. (I also get business quotes from time to time. Hopefully some day I'll get email from a business or person who knows the person who keeps trying to reset their car rental account.)
If you have enough users who forget they already have an account and your signup process makes them get too far before verifying their email address, consider moving email verification earlier in your workflow.
Re: Coinbase user emails and full names leaked
#289Earlier quoted context omitted.
All of you guys seem not to be aware of the things you can do with Bitcoin. Eg: multi-signature wallets. You won't need insurance when the coins simply can't be stolen.
Some Googling only brings up names of exchanges that are working on multi signature wallets. Do you have a link to how to set it up on your own machine?
But there are also some online wallets that already implemented it:
https://www.bitalo.com/ (this one is also at the same time something like localbitcoins.com)
Re: Coinbase user emails and full names leaked
#290Earlier quoted context omitted.
At least at the state level (MA), the automated system is considered an audit. I recently received notice that an "audit" (their word) of my state tax return detected a discrepancy with my federal return. When I called, I was told that it was caught automatically. So I think the manual and automatic processes are considered to be two forms of the broader term "audit".
The IRS does not work for the state of Massachusetts.