Earlier quoted context omitted.
If they had evidence of that, why wouldn't they have pasted it as well? I'm assuming it's baseless speculation. Btw, has anyone actually confirmed any of these emails / names are real? I have a coinbase account and am not mentioned in the leak.
Wouldn't any evidence supporting the existence of the gag order be a violation of the gag order?
Coinbase user emails and full names leaked
31–40 of 294 posts
Re: Coinbase user emails and full names leaked
#32I'm pissed. My email address is among those leaked. I got two transaction requests, the first for 732342.34425 BTC and the second for 999999.99999999 BTC. The second had registered a username of "⚠ URGENT: Сoinbase hacked. We" so that the email subject line read "⚠ URGENT: Сoinbase hacked. We sent you a payment request." I got my coin out of Inputs.io just a few days before they got hacked, and I've got a low balance…
You've just become a target. Everyone now knows everyone on that list has Bitcoin and use web wallets, so it's effectively a list of potentially profitable targets for email account compromise. Please ensure you're using random passwords on every site you use, select the best available security questions, use a password manager, and enable two factor authentication everywhere that allows it. Also move all your coins…
Re: Coinbase user emails and full names leaked
#33Earlier quoted context omitted.
FWIW, https://plus.google.com/people/find You can find people's G+ profile if you guess the email correctly. I wouldn't be surprised if LinkedIn,Facebook,etc. had the same type of thing. I do think that coinbase-API should be rate-limited or unreplayable, but I'm _much more_ interested in where the email-list input data came from. My email wasn't in this alleged partial list, but if it was I'd like to know where they…
You can just type emails into the gmail account creation form to get results back on if the username was taken. This whole debacle is making a mountain out of a molehill.
Re: Coinbase user emails and full names leaked
#34I assume someone took a huge list of emails and ran them through the Coinbase API as described in https://hackerone.com/reports/5200 and retrieved their full names, and is now scaremongering. I do not think they are enumerating users from the coinbase database, but who knows. edit: The recent adobe email list comes to mind.
Re: Coinbase user emails and full names leaked
#35Earlier quoted context omitted.
You've just become a target. Everyone now knows everyone on that list has Bitcoin and use web wallets, so it's effectively a list of potentially profitable targets for email account compromise. Please ensure you're using random passwords on every site you use, select the best available security questions, use a password manager, and enable two factor authentication everywhere that allows it. Also move all your coins…
Hot/cold storage as coinbase is using is probably better than any encryption. Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Manual processing of this means there is some sanity checking on large withdrawals too. Encryption affords you none of that, I would be happier with coinbase than storing on any other online wallet for this very reason.
Were you born yesterday?
The steal-all-your-money rate of bitcoin businesses is running right around 100%, and you're going to lecture people that "they can only ever lose a small portion of all stored user funds"? Really?
Re: Coinbase user emails and full names leaked
#36Earlier quoted context omitted.
Apparent Coinbase response there: "This stance is not unusual on the web: you'll find that user enumeration is possible on Facebook, Google, and nearly every other major internet site" Um, no. If that is what Coinbase believes, I just lost respect for their claims of security.
Would you care explaining why it is that you believe email enumeration to be "insecure"? The data obtained is an email address and a name (only if the user filled in the "name" field). This may as well be treated as public information.
1) Aids phishing attacks against Coinbase and customers
2) Oftentimes harmless tidbits of information can be combined to form non-harmless information. In this case, disclosing email, name, and the fact of being a Coinbase customer, or not, seems minor on its own. However, combine it with some other dataset (let's say emails/passwords taken from an unrelated site), and now it would be easier to break into accounts without setting off warning bells, since you already know who is a user or not.
Dismissing the information disclosure strikes me as akin to the "it's only harmless metadata" argument of the NSA. As we have already seen in many reports, "metadata" can be surprisingly powerful.
Re: Coinbase user emails and full names leaked
#37It's really hard for me to trust anything I read online on April Fools Day.
(Then again, r/games faked moderation corruption as their April Fool's joke. That did not go over well.)
Re: Coinbase user emails and full names leaked
#38Earlier quoted context omitted.
You've just become a target. Everyone now knows everyone on that list has Bitcoin and use web wallets, so it's effectively a list of potentially profitable targets for email account compromise. Please ensure you're using random passwords on every site you use, select the best available security questions, use a password manager, and enable two factor authentication everywhere that allows it. Also move all your coins…
Hot/cold storage as coinbase is using is probably better than any encryption. Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Manual processing of this means there is some sanity checking on large withdrawals too. Encryption affords you none of that, I would be happier with coinbase than storing on any other online wallet for this very reason.
Re: Coinbase user emails and full names leaked
#39Hi, I'm also an account created solely for the purpose of a single submission / comment!
Hi, nothing wrong with anonymity.
Thinking there's "nothing wrong with anonymity" is the kind of intellectual fallacy that makes it so hard to take 'net libertarians seriously.
Re: Coinbase user emails and full names leaked
#40Earlier quoted context omitted.
Hot/cold storage as coinbase is using is probably better than any encryption. Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Manual processing of this means there is some sanity checking on large withdrawals too. Encryption affords you none of that, I would be happier with coinbase than storing on any other online wallet for this very reason.
> Even an end of world bug means that they can only ever lose a small portion of all stored user funds. Were you born yesterday? The steal-all-your-money rate of bitcoin businesses is running right around 100%, and you're going to lecture people that "they can only ever lose a small portion of all stored user funds"? Really?