Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

291–294 of 294 posts

Re: Coinbase user emails and full names leaked

#291
post #166

Earlier quoted context omitted.

You trust Patelco CU and Coinbase employees a lot... Watch out, it might backfire...

If an employee of either company steals from me, I'd expect them to be easily caught. If Coinbase decides to steal 1k from everyone then shutdown that would be crazy since the people behind Coinbase are very well known and in SF; I accepted that risk when I signed up. If someone inside Patelco decides to steal from me, that's a heavly regulated financial establishment - I don't think that person could get away with i…

I wasn't saying they would steal from you. I was referring you trusting their competence to do their job right and not be social-engineered by some hacker into giving them access to your accounts. Thank you for the downvote.

Re: Coinbase user emails and full names leaked

#292

Earlier quoted context omitted.

BofA and Wells Fargo suffer from account number enumeration. Wells Fargo has 10-11 digit (depending on if it's WF or previously Wachovia) account numbers. One portion defines the bank branch where the account was opened, another portion defines the account type, and the last digit is a check digit. You can guess at an account number by attempting a deposit (in person or online). There's also the fact that BofA and We…

Two months ago I was able to enumerate all accounts from a local bank (Paraguay), they used document number and numeric passwords for login. They were showing different error messages when you tried to login with a nonexistent ID. So I started generating random numbers between common document number ranges (1000000-4000000). Our public health system has a web app that lets you check your enrollment status by entering…

isn't this roughly the sort of thing that got weev thrown in jail?

Re: Coinbase user emails and full names leaked

#293

Earlier quoted context omitted.

Two months ago I was able to enumerate all accounts from a local bank (Paraguay), they used document number and numeric passwords for login. They were showing different error messages when you tried to login with a nonexistent ID. So I started generating random numbers between common document number ranges (1000000-4000000). Our public health system has a web app that lets you check your enrollment status by entering…

isn't this roughly the sort of thing that got weev thrown in jail?

Yes, probably. I have communicated the public health app problem (actually they just need to put a CAPTCHA) many times but it seems that nobody cares. About the bank, I was working as a data science consultant at that time, so it was easy for me to knock the door of the security department and tell them about my attack.

Re: Coinbase user emails and full names leaked

#294

Earlier quoted context omitted.

how do you keep track of all the emails? and did you always do this or did you start at one point having to go back through a lot of old accounts to change emails and passwords?

If you use gmail, you can use youremail+anything@gmail.com, and it will all get forwarded to youremail@gmail.com. This is incredibly handy for noticing who is sending you spam. I'll also use it for sites that I know are going to send me spam, and then immediately create a filter than deletes emails sent to joe+annoyingsite@gmail.com (note: that's not my real email)

I've found that when signing up for things, a lot sites don't allow the "+" in the email. They'll throw a email validation error. But at one point this was a good technique, I just think many sites have either don't allow it or can easily get around it
Post reply on HN