Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

11–20 of 135 posts

Re: Update on Coinbase Data Security

#12
I think many users will assume, with a finance site like Coinbase, that the name they have provided is for $ transactions (taxes, Visa, MasterCard, etc.) not for social aspects. In my opinion, getting behind the Privacy Policy and claiming that users know their names will be publicly shared is unethical.

Why people want to hide their names? Personally I don't hide my name. But it is not too hard to understand that on "web-scale" there will be someone who is stalked, who has posted on suicide help forums, etc.

Re: Update on Coinbase Data Security

#13

No mention of the claimed IRS / Fed gag order, interesting. (although I realize its not their main focus right now)

If they have a gag order and they talk about it they go to jail. Probably not going to hear any official word one way or the other.

Re: Update on Coinbase Data Security

#14
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

A few thoughts. I agree with you, which is why we are currently going through a third party security audit in addition to the impromptu peer review by Andreas the day MtGox went down and our normal reviews by accountants. We also hired a director of security from FB. Also, there were rate limits, just not well tuned enough. So it's definitely in focus for us.

Hope this helps clarify

(edited for formatting)

Re: Update on Coinbase Data Security

#16

Rate limiting Do we have to spell it out to them?

Given it's easily parallelizable, assuming the cost of enumeration is significantly lower than other methods and the value of the data is high enough, how does that actually solve anything? All it does is requires someone to rent time on botnets or similar which doesn't seem like it would raise the cost a huge amount at scale.

Re: Update on Coinbase Data Security

#18
We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. This list of emails was likely sourced from other sites - probably Bitcoin related ones. It’s clear there was no data breach because no other user information is provided.

That last sentence is doing a lot of lifting, out of its weight class.

This immediate "no it's not true" might reassure some folks, but it scares me because of how quick it is. Have you looked at the audit systems on your database?

"We believe this information is bogus but are investigating to make sure" is a better response, assuming you actually do investigate to make sure.

Re: Update on Coinbase Data Security

#19
post #10

I'm curious why, given the prior reports of security issues at Coinbase and the ongoing drama with Mt Gox, you guys didn't immediately hire, say, tptacek's company to do extensive penetration testing and a full security audit. It appears that not all API calls were rate-limited, as they probably should have been, and there certainly doesn't seem to be any sort of monitoring of brute-force attempts like this in place.…

This is something that has always bothered me. I've worked in software for awhile now, but never in the financial sector, yet the vast majority of my clients and employers have had third party security audits run on their code and systems. I don't know why every exchange doesn't do this and talk about it publicly.

Re: Update on Coinbase Data Security

#20

No mention of the claimed IRS / Fed gag order, interesting. (although I realize its not their main focus right now)

The gag-order is impossible to disprove. If anything in the release is bullshit, it's that.

I would consider it screamingly obvious that Coinbase reports stuff to the IRS, because they want to run a business, not be crushed to death.

Post reply on HN