Live data from Hacker News

Coinbase user emails and full names leaked

pastebin.com

221–230 of 294 posts

Re: Coinbase user emails and full names leaked

#221
post #206

Earlier quoted context omitted.

Update - blog post here: http://blog.coinbase.com/post/81407694500/update-on-coinbase...

"You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site." I love this. Look these silly free social sites do it, so it must be ok. Anyone know if BofA or WellsFargo allow user enumeration?

> Anyone know if BofA or WellsFargo allow user enumeration

You're correct. They don't. Not even to authorities without a warrant. Which is the point I was trying to make in my earlier comment.[0]

[0] https://news.ycombinator.com/item?id=7510524

Re: Coinbase user emails and full names leaked

#222
post #215
post #192

Earlier quoted context omitted.

Except for the non-zero possibility it could make the difference between you being murdered during a home invasion, or not.

Last time a politician was worried about non- zero probabilities, the U.S. invaded Iraq. I mean, if changing the probability someone's home gets broken into is our standard of practice nowadays there's a lot of companies which will have to close down today.

I reckon non-anonymous bitcoin holders are at greater risk than the average person with money in the bank, since draining the account of the former is a relative cinch once the keys are divulged. The whole crime could be completed within a few minutes.

Re: Coinbase user emails and full names leaked

#223

Earlier quoted context omitted.

They mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

Not saying it was a good reason. Just that they did address the question.

Re: Coinbase user emails and full names leaked

#224
post #36
post #17

Earlier quoted context omitted.

Would you care explaining why it is that you believe email enumeration to be "insecure"? The data obtained is an email address and a name (only if the user filled in the "name" field). This may as well be treated as public information.

It also discloses whether someone is a customer or not. Possibly en masse. Problems: 1) Aids phishing attacks against Coinbase and customers 2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/password…

While I don't find Coinbase's response here reassuring, if you work with a business whose bizmodel is "people can send money to your email address" then it becomes essentially impossible to stop someone from verifying that your address exists.

Re: Coinbase user emails and full names leaked

#225
post #206

Earlier quoted context omitted.

Update - blog post here: http://blog.coinbase.com/post/81407694500/update-on-coinbase...

"You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site." I love this. Look these silly free social sites do it, so it must be ok. Anyone know if BofA or WellsFargo allow user enumeration?

BofA and Wells Fargo suffer from account number enumeration.

Wells Fargo has 10-11 digit (depending on if it's WF or previously Wachovia) account numbers. One portion defines the bank branch where the account was opened, another portion defines the account type, and the last digit is a check digit. You can guess at an account number by attempting a deposit (in person or online).

There's also the fact that BofA and Wells Fargo have account numbers displayed in cleartext on pieces of paper that are handed to strangers.

I'm not arguing the merits of Coinbase's security, but traditional banks don't fare well either. Coinbase can improve. Traditional banks are limited by standards that they can't change.

Re: Coinbase user emails and full names leaked

#226
post #137

Earlier quoted context omitted.

Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.

Would you include in your response the reason why you're ignoring Homakov's security flaw reports, which were emailed to you at your whitehat@coinbase.com email address? https://news.ycombinator.com/item?id=7505757 A lot of people are getting nervous that you're not taking security seriously at Coinbase. Ignoring whitehat reports would seem to be a serious issue.

Their official response did not give any reason for ignoring the reports, nor did it even acknowledge that this happened. Disappointing.

Re: Coinbase user emails and full names leaked

#227
post #209

Earlier quoted context omitted.

It does confirm email addresses you can guess though (which are not necessarily email addresses you have , until they're confirmed), along with leaking other information about that user.

What other information is it leaking?

From what I gather, first name and last name.

Stopping email address validation is, I think, impossible for a company like Coinbase, but revealing the name doesn't have to happen.

On the other hand, providing the first and last name could be very valuable to the users, though. If I send coins to bob@example.com, I'd like to see the real name behind that address.

On the other other hand, if anyone can make any first and last name they wish, then the safety of that goes away. Maybe I make b0b@example.com with the same real name.

EDIT The users agreed to have their names given to people they transact with. Does that include strangers attempting to transact with them? I'm thinking "no" but can see the other side.

Re: Coinbase user emails and full names leaked

#228

Earlier quoted context omitted.

Apropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free : they'll cost you some tech support cycles.

Cheap, sure, but they'll cost you plenty in "lost face" when we journos write that you ignored inbound alerts from the person who later published something out of frustration. Not just emails, either. See also event logging: https://www.schneier.com/blog/archives/2014/03/details_of_th...

Seriously, this. They are being nonchalant about this whole thing, but it may be damaging their most valuable asset - the community's trust in them. Just don't ignore repeated attempts to contact your whitehat address.

Re: Coinbase user emails and full names leaked

#229
post #208

Earlier quoted context omitted.

They're now "morons" to allow people to send payment requests? Perhaps you're not quite familiar with their business model.

I am well-familiar as I'm an early adopter (and sufferer), but how about having a button "report spam/scam"? If I "decline", the attacker will get a confirmation I'm logged into my account and my email and account are verified!

I'd imagine it's one of those not-really-needed-until-it-is feature. And now, due to all this crying, they'll implement such a "I don't know this person" option.

Re: Coinbase user emails and full names leaked

#230

Earlier quoted context omitted.

"You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site." I love this. Look these silly free social sites do it, so it must be ok. Anyone know if BofA or WellsFargo allow user enumeration?

BofA and Wells Fargo suffer from account number enumeration. Wells Fargo has 10-11 digit (depending on if it's WF or previously Wachovia) account numbers. One portion defines the bank branch where the account was opened, another portion defines the account type, and the last digit is a check digit. You can guess at an account number by attempting a deposit (in person or online). There's also the fact that BofA and We…

I haven't personally seen the system, or tested it, but I'm pretty sure if I tried to enumerate all Bank Of America account numbers I'd get shut down pretty quick.
Post reply on HN