Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

281–290 of 294 posts

Re: Coinbase user emails and full names leaked

#281
post #137

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.

You are a fucking dick for ignoring that guy..just saying

Re: Coinbase user emails and full names leaked

#282
post #105

Does anyone know where or if the full list can be found? I have a Coinbase account but I don't see my name on the abbreviated list. I suspect that the person who made this Pastebin just ran a huge list of known leaked emails, or dictionary based emails through the minor information leakage vulnerability discussed yesterday ( https://hackerone.com/reports/5200 ). I would be willing to bet that this brief list is actua…

There is no full list. The "exploit" doesn't give you email addresses you don't already have. This is why it was not considered a vulnerability.

I think you meant to say :

"This is the bullshit excuse they are trying to use to make it SEEM like its not a vulnerability."

Coinbase is deliberately misleading their users regarding privacy if they do not fix this issue!

Re: Coinbase user emails and full names leaked

#283

Earlier quoted context omitted.

I work on dating sites, some of them a bit risqué. On the password reset form, there's a big difference between saying "That email does not exist in our system"/"Emailed password reset instructions" vs "If that account is registered, we will email you instructions".

How do you handle users attempting to register a new account with an email address that already exists? If you say, "we don't allow two accounts with the same email address", you have the same issue as coinbase.

For the case of people attempting to sign up a second time with the same email address, don't change anything shown from the webpage. Instead of sending a verification email, send an email informing them that someone is trying to sign up again with the same email address, and include an expiring password reset link in that email. If you see too many users forgetting that they've already signed up, and getting frustrated by filling out too much data in forms before finding out they've already signed up, then consider moving the email verification step earlier in the signup process.

Re: Coinbase user emails and full names leaked

#284

Earlier quoted context omitted.

What other information is it leaking?

From what I gather, first name and last name. Stopping email address validation is, I think, impossible for a company like Coinbase, but revealing the name doesn't have to happen. On the other hand, providing the first and last name could be very valuable to the users, though. If I send coins to bob@example.com, I'd like to see the real name behind that address. On the other other hand, if anyone can make any first a…

If you want a service that allows the sender to verify name before sending, make it a feature that both:

(1) is opt-in on the recipient's side and fails with something like "that recipient email address doesn't have an account, the name doesn't match, or they haven't decided to allow name verification"

AND

(2) is only available on payments above your highest guess at the expected value of matching an account-email-name triple for spearphishing, and the error messages (and timings) are identical if the name doesn't match or the given email address doesn't have an account.

I imagine there are few profitable attacks where an answer "yes, email_address with name has a Coinbase account" costs a minimum of 100 USD to an attacker and getting an answer "Either email_address doesn't have an account, that name doesn't match our records, or they've chosen not to share their name" costs 0 USD. However, I'd have to think a bit more about that 100 USD minimum.

Re: Coinbase user emails and full names leaked

#286
post #283

Earlier quoted context omitted.

How do you handle users attempting to register a new account with an email address that already exists? If you say, "we don't allow two accounts with the same email address", you have the same issue as coinbase.

For the case of people attempting to sign up a second time with the same email address, don't change anything shown from the webpage. Instead of sending a verification email, send an email informing them that someone is trying to sign up again with the same email address, and include an expiring password reset link in that email. If you see too many users forgetting that they've already signed up, and getting frustra…

So you'll allow a user to go all the way through the process of registration, create a new password, get temporary access to your site... and then what... not save that password? So a re-login attempt won't work?

I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.

Re: Coinbase user emails and full names leaked

#287

Earlier quoted context omitted.

What does that have to do with what I said? I think the manner in which you made your point has too high a chance of being misinterpreted to be acceptable here, which is probably why it was being downvoted.

I get your point, yet somebody misinterpreting a joke should have no impact on the company... Unless the company actually had inadequate reserves to meet customer withdrawals, thus leaving the solvency of the company at risk of a good old-fashioned fractional reserve style bank-run...

Oh, I could care less about the company, but I do care about the integrity of HN as a whole. That doesn't mean I don't like the occasional joke on here either, but since that story seemed a bit light on details and people were looking for information, posting satire that looks very much like valid information can be unintentionally misleading.

Re: Coinbase user emails and full names leaked

#288
post #283

Earlier quoted context omitted.

For the case of people attempting to sign up a second time with the same email address, don't change anything shown from the webpage. Instead of sending a verification email, send an email informing them that someone is trying to sign up again with the same email address, and include an expiring password reset link in that email. If you see too many users forgetting that they've already signed up, and getting frustra…

So you'll allow a user to go all the way through the process of registration, create a new password, get temporary access to your site... and then what... not save that password? So a re-login attempt won't work? I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.

> ... get temporary access to your site...

> I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.

The workflow diverges at the email verification step, before you grant any access to the site. Existing users get an email informing them that someone has tried to sign up a second time using their email address while new users get the standard email verification email.

I highly recommend not allowing account creation before email address verification. I have a difficult to spell last name, so I have one email address that contains my initials and a common word instead of my last name. You'd be surprised the number of people who don't know their own email address and the number of sites that allow people to sign up (and apparently transact significantly) without verifying email addresses. Off the top of my head, if I wanted to, I could steal one person's tax accounting account (I got confirmation that they filed their state taxes this year, and later confirmation their state accepted their filing), another person's car rental account, and a third person's business's trash service account. From time to time the one person tries to reset their car rental account password. I imagine I could reset the passwords for all of these accounts (and others) and get the last 4 digits of their credit card numbers and other personal information and use that as a starting point for gaining access to other accounts they own. In the case of the tax account, I could probably re-download the tax paperwork and get their SSN. Neither the tax accounting company nor the car rental agency replied when I informed them that accounts were set up with the wrong email addresses. (I also get business quotes from time to time. Hopefully some day I'll get email from a business or person who knows the person who keeps trying to reset their car rental account.)

If you have enough users who forget they already have an account and your signup process makes them get too far before verifying their email address, consider moving email verification earlier in your workflow.

Re: Coinbase user emails and full names leaked

#289

Earlier quoted context omitted.

All of you guys seem not to be aware of the things you can do with Bitcoin. Eg: multi-signature wallets. You won't need insurance when the coins simply can't be stolen.

Some Googling only brings up names of exchanges that are working on multi signature wallets. Do you have a link to how to set it up on your own machine?

Sure: https://www.youtube.com/watch?v=zIbUSaZBJgU

But there are also some online wallets that already implemented it:

https://greenaddress.it/en/

https://www.bitgo.com/

https://www.bitalo.com/ (this one is also at the same time something like localbitcoins.com)

Re: Coinbase user emails and full names leaked

#290

Earlier quoted context omitted.

At least at the state level (MA), the automated system is considered an audit. I recently received notice that an "audit" (their word) of my state tax return detected a discrepancy with my federal return. When I called, I was told that it was caught automatically. So I think the manual and automatic processes are considered to be two forms of the broader term "audit".

The IRS does not work for the state of Massachusetts.

We know this. I was explaining to you what the word means by example.
Post reply on HN