Live data from Hacker News

Update on Coinbase Data Security

blog.coinbase.com

41–50 of 135 posts

Re: Update on Coinbase Data Security

#41
post #4

Earlier quoted context omitted.

From the text: "For example, we employ rate limits around sensitive actions, such as requesting money, to prevent them from being abused at scale."

They don't appear to be rate limiting their API that allows enumeration of first and last names. Also, We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase. There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinba…

Actually over a million: http://blog.coinbase.com/post/78016535692/a-major-coinbase-m...

Re: Update on Coinbase Data Security

#42
post #37
post #33

Earlier quoted context omitted.

You conveniently left out their next sentence "... many leading payment services allow user enumeration, including Paypal, Venmo, Square Cash, and many others..."

Because I was talking about banks & processors, not payment services. Paypal will cut you off hard if you attempt to bulk enumerate users/businesses by e-mail address, so this is even more disingenuous on the part of Coinbase.

There's only one explanation for why you can't get service for problems unless you're featured on reddit, why they don't care about security, and why they're flagrantly dishonest in their comparisons: because they don't respect us, at all.

Re: Update on Coinbase Data Security

#43
post #6

Earlier quoted context omitted.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Many people automatically assume that this word means something bad. Something about "cetic" makes them think "septic" or "toxic" even. I've had to explain the word a few times to co-workers. I picked it up from a crappy song, come on guys!

Local H?

Re: Update on Coinbase Data Security

#44
post #6

Earlier quoted context omitted.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Many people automatically assume that this word means something bad. Something about "cetic" makes them think "septic" or "toxic" even. I've had to explain the word a few times to co-workers. I picked it up from a crappy song, come on guys!

It sounds like somebody with a lisp saying "pathetic", hence the negative association (for me at least).

Re: Update on Coinbase Data Security

#45
post #6
post #2

Less sympathetic than I was hoping for but copacetic. Could they have nipped this in the bud with a faster response? Perhaps. However having dealt with reports like this, I cannot recall a decent interaction with a reporter.

copacetic : in excellent order. (For the lazy like me, who still want to learn new and useful words.)

Hmmm...I might have to refine my use of the word. I'm more familiar with "very satisfactory" which is what I had in mind here.

Re: Update on Coinbase Data Security

#46
post #21

You’ll find that user enumeration is possible on Facebook, Google, Dropbox, and nearly every other major internet site. And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.

As mentioned in the blog post, payment services also commonly allow user enumeration, including Paypal, Venmo, Square Cash, and others. The reason you don't see it with banks is that they don't allow you to send money to an email address.

I don't know about the other large US banks, but Chase definitely does and has been for years.

Re: Update on Coinbase Data Security

#47
post #39
post #36

Earlier quoted context omitted.

'We didn't do anything wrong, this isn't a bug, nothing to see here.' despite obvious evidence to the contrary. Very confidence inducing.

For those of us getting caught up on these events - what evidence are you referring to? So far I've seen : 1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders 2) Homakov's email to whitehat@ concerning a potential iframe vuln What am I missing?

If I'm reading correctly: Coinbase provided confirmation that the email addresses on pastebin are Coinbase customers, and also provided the associated names. Coinbase doesn't think that's a serious issue.

Re: Update on Coinbase Data Security

#49
If Coinbase can't admit any amount of fault whatsoever for enabling the large-scale harvesting of their customer list, I'm sorry, but I've lost faith in their security.

This is a service that stores digital cash. It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.

Re: Update on Coinbase Data Security

#50

Rate limiting Do we have to spell it out to them?

Given it's easily parallelizable, assuming the cost of enumeration is significantly lower than other methods and the value of the data is high enough, how does that actually solve anything? All it does is requires someone to rent time on botnets or similar which doesn't seem like it would raise the cost a huge amount at scale.

Already a largely solved problem. If you try enumerating email addresses by running through queries at Hotmail or Yahoo, for example, they'll shut the doors on you in a matter of seconds. Think you can just use thousands of IPs instead? Go for it - they trust 'new' and rarely-seen IP addresses even less, and bring up the shutters all the faster. It's not a new problem, and there's lots of best practice to learn from, for anyone who wants to do it right.
Post reply on HN