Divulging a name when presented with an email address is pretty bad and I'm not sure why it would be necessary. Just confirming that an email address is in the system is fairly minor.
Coinbase says the name is optional, so only people that chose to share their name are affected.
Coinbase design allows for mass, targeted phishing of its users
71–75 of 75 posts
Re: Coinbase design allows for mass, targeted phishing of its users
#72There's another bug when you can substitute coinbase's iframe with your own, when you use coinbase button. This iframe can ask for username / password, and there's no way for user to distinguish fake iframe from real. They also not into replying emails on their whitehat@ address.
+ there was another bug (or "feature") that allowed all access to all funds via API access key. Sure, the user needs to allow the permissions first, but the warning where disproportionate to the power it gave away. They've disabled this kind of access since though. http://www.theverge.com/2014/2/7/5386222/a-string-of-thefts-...
Re: Coinbase design allows for mass, targeted phishing of its users
#73Re: Coinbase design allows for mass, targeted phishing of its users
#74Earlier quoted context omitted.
No, since there's no way to check iframe's domain I don't think it can be fixed for iframes . They should stop asking for user's password right there, because it makes people trust any iframe
Maybe they can force login via their main site first. Lousier user experience though.
Re: Coinbase design allows for mass, targeted phishing of its users
#75Earlier quoted context omitted.
Maybe they can force login via their main site first. Lousier user experience though.
Lousy user experience is not being able to verify what site I'm about to enter my payment credentials into.